First published: Tue Apr 08 2025(Updated: )
A vulnerability has been found in ESAFENET CDG 5.6.3.154.205_20250114 and classified as critical. This vulnerability affects unknown code of the file /parameter/getLimitIPList.jsp. The manipulation of the argument noticeId leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gemalto SafeNet CDG | ||
Gemalto SafeNet CDG | =5.6.3.154.205_20250114 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3401 is classified as a critical vulnerability.
CVE-2025-3401 affects the file /parameter/getLimitIPList.jsp in ESAFENET CDG 5.6.3.154.205_20250114.
CVE-2025-3401 enables SQL injection attacks.
CVE-2025-3401 can be exploited remotely.
To mitigate CVE-2025-3401, ensure that ESAFENET CDG is updated to a patched version that addresses this SQL injection vulnerability.