First published: Mon Apr 08 2024(Updated: )
A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /admin/config_ISCGroupNoCache.php. The manipulation of the argument GroupId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259713 was assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Netentsec NS-ASG Application Security Gateway | ||
Netentsec Application Security Gateway | =6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3457 is classified as a critical vulnerability.
CVE-2024-3457 allows for SQL injection through manipulation of the GroupId argument in the /admin/config_ISCGroupNoCache.php file.
Mitigation for CVE-2024-3457 involves applying any available security patches from Netentsec for the NS-ASG Application Security Gateway.
CVE-2024-3457 affects Netentsec NS-ASG Application Security Gateway version 6.3.
CVE-2024-3457 can potentially allow attackers to access and manipulate the database through SQL injection.