ZeroHour

CVE-2023-22620

PoC ×3
CVSS 3.1
7.5 high
EPSS
4%p90
Published
()
Modified
Description

An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an invalid authentication attempt. This can afterwards be used to bypass the device's authentication and get access to the administrative interface.

Vendors
securepoint
Products
unified threat management
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.