CVE-2023-22620

CVSS V2 None CVSS V3 None
Description
An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an invalid authentication attempt. This can afterwards be used to bypass the device's authentication and get access to the administrative interface.
Overview
  • CVE ID
  • CVE-2023-22620
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-04-12T23:15:06
  • Last Modified Date
  • 2023-04-21T15:34:20
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:o:securepoint:unified_threat_management:*:*:*:*:*:*:*:* 1 OR 12.2.3.1 12.2.5.1
History
Created Old Value New Value Data Type Notes
2023-04-17 04:39:35 Added to TrackCVE
2023-04-18 10:00:24 2023-04-18T09:15:08 CVE Modified Date updated
2023-04-18 10:00:25 References updated
2023-04-18 15:00:27 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-04-18 21:00:47 2023-04-18T20:15:18 CVE Modified Date updated
2023-04-18 21:00:50 References updated
2023-04-21 16:00:56 2023-04-21T15:34:20 CVE Modified Date updated
2023-04-21 16:00:56 Undergoing Analysis Analyzed Vulnerability Status updated
2023-04-21 16:00:58 Weakness Enumeration new
2023-04-21 16:01:00 CPE Information updated