PT-2024-23636 · Netentsec · Netentsec Ns-Asg
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
netentsec NS-ASG version 6.3
Description
The issue concerns a SQL injection vulnerability. It can be exploited via the "/admin/config ISCGroupSSLCert.php" API endpoint. This could potentially allow for remote attacks.
Recommendations
For netentsec NS-ASG version 6.3, patch immediately and validate input data to prevent exploitation.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netentsec Ns-Asg