6.5
CVSSv3

CVE-2023-22897

Published: 12/04/2023 Updated: 21/04/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An issue exists in SecurePoint UTM prior to 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows information disclosure of memory contents to be achieved by an authenticated user. Essentially, uninitialized data can be retrieved via an approach in which a sessionid is obtained but not used.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

securepoint unified threat management

Exploits

SecurePoint UTM versions 12x suffers from a memory leak vulnerability via the spcgicgi endpoint ...