CVE-2023-23952: Command Injection
Published Jun 1, 2023
·Updated
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability.
Affected Software
2 affected components
Broadcom Advanced Secure Gateway<7.3.13.1
Broadcom Content Analysis<3.1.6.0
Event History
Jun 1, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
01:15 AM
Description
Frequently Asked Questions
1
What is CVE-2023-23952?
CVE-2023-23952 is a Command Injection vulnerability found in Advanced Secure Gateway and Content Analysis prior to 7.3.13.1 / 3.1.6.0.
2
How severe is CVE-2023-23952?
CVE-2023-23952 has a severity score of 9.8 (critical).
3
Which software versions are affected by CVE-2023-23952?
Advanced Secure Gateway versions prior to 7.3.13.1 and Content Analysis versions prior to 3.1.6.0 are affected by CVE-2023-23952.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-23952?
The CWE ID for CVE-2023-23952 is CWE-77 (Improper Neutralization of Special Elements used in a Command ('Command Injection')).
5
How can I fix CVE-2023-23952?
To fix CVE-2023-23952, it is recommended to update Advanced Secure Gateway to version 7.3.13.1 or later, and Content Analysis to version 3.1.6.0 or later.