PT-2026-103682 · Genians · Genian Nac 4.0.175 Release+8
CVSS v4.0
5.9
Medium
| Vector | AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code
Fix
Path traversal
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Genian Nac 4.0.175 Release
Genian Nac 5.0.65 Lts Release
Genian Nac 5.0.75 Lts Release
Genian Nac 5.0.85 Release Stable
Genian Nac 5.0.86 Release
Genian Ztna 6.0.26 Lts Release
Genian Ztna 6.0.35 Lts Release
Genian Ztna 6.0.45 Release Stable
Genian Ztna 6.0.46 Release