CVE-2024-2330
Netentsec NS-ASG Application Security Gateway index.php sql injection
Record summary
CVE-2024-2330 has a selected CVSS score of 6.3 (medium); EIP currently links 1 Nuclei template.
Description
A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This affects an unknown part of the file /protocol/index.php. The manipulation of the argument IPAddr leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256281 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 26, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 12, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
NS-ASG Application Security GatewayBrowse Netentsec / NS-ASG Application Security Gateway | CVE List, VulnCheck | 6.3 | affected |
application_security_gatewayBrowse netentsec / application_security_gatewayDefault status: unknown | CVE List | 6.3 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMNS-ASG Application Security Gateway 6.3 - Sql InjectionCVSS 6.3
A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This affects an unknown part of the file /protocol/index.php. The manipulation of the argument IPAddr leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Impact
Authenticated attackers can extract sensitive database information via SQL injection in the NS-ASG Application Security Gateway.
Remediation
Update NS-ASG Application Security Gateway to a version newer than 6.3.
Source: ProjectDiscovery