CVE-2023-22897

CVSS V2 None CVSS V3 None
Description
An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows information disclosure of memory contents to be achieved by an authenticated user. Essentially, uninitialized data can be retrieved via an approach in which a sessionid is obtained but not used.
Overview
  • CVE ID
  • CVE-2023-22897
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-04-12T23:15:07
  • Last Modified Date
  • 2023-04-21T18:10:37
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:o:securepoint:unified_threat_management:*:*:*:*:*:*:*:* 1 OR 12.2.3.1 12.2.5.1
History
Created Old Value New Value Data Type Notes
2023-04-17 04:39:36 Added to TrackCVE
2023-04-18 10:00:26 2023-04-18T09:15:08 CVE Modified Date updated
2023-04-18 10:00:26 References updated
2023-04-18 15:00:28 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-04-18 21:00:47 2023-04-18T20:15:18 CVE Modified Date updated
2023-04-18 21:00:50 References updated
2023-04-21 19:00:57 2023-04-21T18:10:37 CVE Modified Date updated
2023-04-21 19:00:57 Undergoing Analysis Analyzed Vulnerability Status updated
2023-04-21 19:00:59 Weakness Enumeration new
2023-04-21 19:01:01 CPE Information updated