7.5
CVSSv3

CVE-2023-22620

Published: 12/04/2023 Updated: 21/04/2023
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 0

Vulnerability Summary

An issue exists in SecurePoint UTM prior to 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an invalid authentication attempt. This can afterwards be used to bypass the device's authentication and get access to the administrative interface.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

securepoint unified threat management

Exploits

SecurePoint UTM versions 12x suffers from a session identifier leak vulnerability via the spcgicgi endpoint ...

Github Repositories

The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of Netlas.io.

Welcome to Netlas CookBook! The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of Netlasio ⭐️ Give us a star to show your appreciation 👁️ Subscribe for updates Table of contents What is Netlasio? Simple usage examp