An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows information disclosure of memory contents to be achieved by an authenticated user. Essentially, uninitialized data can be retrieved via an approach in which a sessionid is obtained but not used.
CVE Infomation | Exploits or more Infomation |
---|---|
mitre | EXPLOIT DATABASE |
NVD | 0day.today |
vulmon.com | github |
CVE Details | |
JVN ENG JPN | |
Reconshell |
Software Tag:
List of frequently cited URLs
URL | Num of Times Referred to |
---|---|
https://alerts.vulmon.com/?utm_source=twitter&utm_medium=so... | 209 |
https://www.rcesecurity.com/2023/04/securepwn-part-2-leakin... | 7 |
List of frequently cited URLs
URL | Num of Times Referred to |
---|---|
alerts.vulmon.com | 209 |
www.rcesecurity.com | 7 |
Name | URL |
---|---|
No Data |
Name | URL |
---|---|
No Data |