PT-2024-25993 · Netentsec · Netentsec Ns-Asg Application Security Gateway

Chenzefeng

·

Published

2024-04-08

·

Updated

2024-05-17

·

CVE-2024-3458

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netentsec NS-ASG Application Security Gateway version 6.3
Description A critical vulnerability was found in the Netentsec NS-ASG Application Security Gateway. This issue affects the file /admin/add ikev2.php and is caused by the manipulation of the TunnelId argument, leading to SQL injection. The attack can be initiated remotely.
Recommendations For version 6.3, consider disabling access to the /admin/add ikev2.php file until a patch is available. Restrict the manipulation of the TunnelId argument to minimize the risk of SQL injection. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-3458

Affected Products

Netentsec Ns-Asg Application Security Gateway