PT-2024-21397 · Netentsec · Netentsec Ns-Asg Application Security Gateway

·

CVE-2024-2648

·

Published

2024-03-19

·

Updated

2025-01-30

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Netentsec NS-ASG Application Security Gateway version 6.3
Description A problematic issue was found in the affected software, where an unknown function of the file /nac/naccheck.php is impacted. The manipulation of the username argument leads to improper neutralization of data within xpath expressions. This allows for a remote attack. The issue has been publicly disclosed and may be exploited.
Recommendations Netentsec NS-ASG Application Security Gateway version 6.3: Update the software to a version where this issue is resolved, or apply a patch if provided by the vendor to fix the improper neutralization of data within xpath expressions. As a temporary workaround, consider restricting access to the /nac/naccheck.php file or disabling the unknown function impacted by this issue until a patch is available. Avoid using the username argument in the affected function until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-2648

Affected Products

Netentsec Ns-Asg Application Security Gateway