CVE-2023-30803: Sangfor Next-Gen Application Firewall Authentication Bypass
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can bypass authentication and access administrative functionality by sending HTTP requests using a crafted Y-forwarded-for header.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Sangfor Next-Gen Application Firewall vulnerability?
The vulnerability ID is CVE-2023-30803.
What is the severity rating of CVE-2023-30803?
The severity rating of CVE-2023-30803 is critical with a CVSS score of 9.8.
What software version is affected by this vulnerability?
The Sangfor Next-Gen Application Firewall version 8.0.17 is affected by this vulnerability.
How can an attacker exploit CVE-2023-30803?
An attacker can exploit CVE-2023-30803 by sending HTTP requests with a crafted Y-forwarded-for header to bypass authentication and access administrative functionality.
Are there any references available for CVE-2023-30803?
Yes, there are references available for CVE-2023-30803. You can find them at the following links: [Reference 1](https://aws.amazon.com/marketplace/pp/prodview-uujwjffddxzp4), [Reference 2](https://labs.watchtowr.com/yet-more-unauth-remote-command-execution-vulns-in-firewalls-sangfor-edition/), [Reference 3](https://vulncheck.com/advisories/sangfor-ngaf-auth-bypass).