CVE-2023-30804: Sangfor Next-Gen Application Firewall Authenticated File Disclosure
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authenticated file disclosure vulnerability. A remote and authenticated attacker can read arbitrary system files using the svpnhtml/loadfile.php endpoint. This issue is exploitable by a remote and unauthenticated attacker when paired with CVE-2023-30803.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-30804?
CVE-2023-30804 is a vulnerability in the Sangfor Next-Gen Application Firewall version NGAF8.0.17 that allows an authenticated attacker to read arbitrary system files.
What is the severity of CVE-2023-30804?
The severity of CVE-2023-30804 is medium with a CVSS score of 6.5.
How does CVE-2023-30804 affect Sangfor Next-Gen Application Firewall?
CVE-2023-30804 affects Sangfor Next-Gen Application Firewall version NGAF8.0.17, allowing an authenticated attacker to read arbitrary system files.
How can the CVE-2023-30804 vulnerability be exploited?
The CVE-2023-30804 vulnerability can be exploited by a remote and authenticated attacker through the svpn_html/loadfile.php endpoint.
Is CVE-2023-30804 fixable?
Yes, the Sangfor Next-Gen Application Firewall can be fixed by updating to a version that is not affected by the CVE-2023-30804 vulnerability.