CVE-2017-6315: Input Validation
Published Sep 19, 2017
·Updated
Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx.
Affected Software
3 affected components
Sophos Astaro Security Gateway Firmware=7.500
Sophos Astaro Security Gateway Firmware=7.506
Sophos Astaro Security Gateway
Event History
Sep 19, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-6315?
CVE-2017-6315 is classified as a critical vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2017-6315?
To remediate CVE-2017-6315, update the Sophos Astaro Security Gateway firmware to version 7.507 or later.
3
What are the affected versions for CVE-2017-6315?
CVE-2017-6315 affects Sophos Astaro Security Gateway versions 7.500 and 7.506.
4
Can CVE-2017-6315 be exploited remotely?
Yes, CVE-2017-6315 can be exploited by remote attackers through a crafted request to index.plx.
5
What types of attacks does CVE-2017-6315 allow?
CVE-2017-6315 allows remote attackers to execute arbitrary code on the affected device.