CVE-2018-5403

HIGH

Imperva SecureSphere <v13 - RCE

Title source: llm
STIX 2.1

Description

Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basic authentication passwords, the GW may be vulnerable to RCE through specially crafted requests, from the web access management interface.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rsp3ar · pythonwebappslinux
https://www.exploit-db.com/exploits/45542

Scores

CVSS v3 8.1
EPSS 0.0467
EPSS Percentile 89.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287 CWE-77
Status published
Products (3)
imperva/securesphere 13.0.10
imperva/securesphere 13.1.10
imperva/securesphere 13.2.10
Published Jan 10, 2019
Tracked Since Feb 18, 2026