CVE-2023-22897
An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows information disclosure of memory contents to be achieved by an authenticated user. Essentially, uninitialized data can be retrieved via an approach in which a sessionid is obtained but not used.
- Affected products
- Securepoint Utm
- Securepoint Unified Threat Management
- < 12.2.5.1
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 4.1% (90th percentile)
- Weakness
- CWE-908
- NVD status
- Modified
- Published
- 2023-04-12
CVE-2023-22897 at NVD
3 known exploits for CVE-2023-22897
Proof-of-concept code and exploit modules indexed by Sploitus