PT-2024-25964 · Netentsec · Netentsec Ns-Asg Application Security Gateway

Zerone0X00

·

Published

2024-04-08

·

Updated

2024-05-17

·

CVE-2024-3455

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netentsec NS-ASG Application Security Gateway version 6.3
Description A critical issue has been found in the Netentsec NS-ASG Application Security Gateway. The vulnerability affects an unknown functionality of the file /admin/add postlogin.php. The manipulation of the SingleLoginId argument leads to SQL injection. This issue can be exploited remotely. The exploit has been disclosed to the public and may be used.
Recommendations For Netentsec NS-ASG Application Security Gateway version 6.3, consider disabling access to the /admin/add postlogin.php file until a patch is available. As a temporary workaround, restrict the manipulation of the SingleLoginId argument to minimize the risk of SQL injection exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-3455

Affected Products

Netentsec Ns-Asg Application Security Gateway