CVE-2023-30805: Sangfor Next-Gen Application Firewall Login Un Param Command Injection
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /LogInOut.php endpoint. This is due to mishandling of shell meta-characters in the "un" parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-30805?
CVE-2023-30805 is an operating system command injection vulnerability in the Sangfor Next-Gen Application Firewall version NGAF8.0.17.
How severe is CVE-2023-30805?
CVE-2023-30805 has a severity rating of 9.8 (critical).
How does CVE-2023-30805 affect Sangfor Next-Gen Application Firewall?
CVE-2023-30805 allows remote and unauthenticated attackers to execute arbitrary commands by sending a crafted HTTP POST request to the /LogInOut.php endpoint.
How can I fix CVE-2023-30805?
To fix CVE-2023-30805, it is recommended to update the Sangfor Next-Gen Application Firewall to a version that is not affected by this vulnerability.
Are there any references for CVE-2023-30805?
Yes, you can find more information about CVE-2023-30805 at the following references: [Link 1](https://aws.amazon.com/marketplace/pp/prodview-uujwjffddxzp4), [Link 2](https://labs.watchtowr.com/yet-more-unauth-remote-command-execution-vulns-in-firewalls-sangfor-edition/), [Link 3](https://vulncheck.com/advisories/sangfor-ngaf-username-rce).