HIGH · 8.8

CVE-2022-23767

This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerab...

Vulnerability Description

This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform various attacks such as obtaining privileges and executing remote code, thereby taking over the victim’s system.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
HanssakSecuregate3.5
HanssakWeblink>= 3.5.2, <= 3.5.5
MicrosoftWindows-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-23767?

CVE-2022-23767 is a vulnerability with a CVSS score of 8.8 (HIGH). This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerab...

How severe is CVE-2022-23767?

CVE-2022-23767 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-23767?

Check the references section above for vendor advisories and patch information. Affected products include: Hanssak Securegate, Hanssak Weblink, Microsoft Windows.