CVE-2023-40253: OS Command Injection
Improper Authentication vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Authentication Abuse.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Genian NAC V5.0: from V5.0.0 through V5.0.42 (Revision 117460); Genian NAC Suite V5.0: from V5.0.0 through V5.0.54; Genian ZTNA: from V6.0.0 through V6.0.15.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-40253.
What software is affected by this vulnerability?
Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, and Genians Genian ZTNA are affected by this vulnerability.
What is the severity of CVE-2023-40253?
The severity of CVE-2023-40253 is critical, with a severity value of 9.8.
How do I fix the CVE-2023-40253 vulnerability?
To fix the CVE-2023-40253 vulnerability, it is recommended to update Genians Genian NAC to version 4.0.156 or later, or Genians Genian NAC V5.0 to version 5.0.55 or later. For Genians Genian ZTNA, update to version 6.0.16 or later.
Where can I find more information about CVE-2023-40253?
You can find more information about CVE-2023-40253 at the following link: [Genians Genian NAC Advisory](https://docs.genians.com/nac/5.0/release/ko/advisories/GN-SA-2023-001.html)