CVE-2023-7308
SecGate3600, a network firewall product developed by NSFOCUS, contains a sensitive information disclosure vulnerability in the /cgi-bin/authUser/authManageSet.cgi endpoint.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.12%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SecGate3600, a network firewall product developed by NSFOCUS, contains a sensitive information disclosure vulnerability in the /cgi-bin/authUser/authManageSet.cgi endpoint. The affected component fails to enforce authentication checks on POST requests to retrieve user data. An unauthenticated remote attacker can exploit this flaw to obtain sensitive information, including user identifiers and configuration details, by sending crafted requests to the vulnerable endpoint. An affected version range is undefined. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-06-18 UTC.
- CVSS 4.0
- 8.7 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 7.12% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- nsfocusglobal/secgate3600 firmware
- Source
- disclosure@vulncheck.com
References
- https://github.com/jjjj1029056414/selfpoc/blob/main/wangshen-SecGate3600-information-leakage.pyExploit
- https://nsfocusglobal.com/products/next-gen-firewall-2/Product
- https://www.vulncheck.com/advisories/secgate3600-firewall-info-discThird Party Advisory
- https://www.vulncheck.com/advisories/secgate3600-firewall-info-discThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.