First published: Fri Dec 29 2023(Updated: )
A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3.1. This affects an unknown part of the file index.php?para=index of the component Login. The manipulation of the argument check_VirtualSiteId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249183.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Netentsec Application Security Gateway firmware | =6.3.1 | |
Netentsec Application Security Gateway |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-7161 has been classified as a critical vulnerability.
CVE-2023-7161 affects the Login component by allowing SQL injection through the index.php?para=index file manipulation.
To fix CVE-2023-7161, upgrade the Netentsec Application Security Gateway firmware to a version that addresses this vulnerability.
CVE-2023-7161 impacts the Login component of the application.
Yes, version 6.3.1 of the Netentsec Application Security Gateway is vulnerable to CVE-2023-7161.