VYPR

Next Gen Application Firewall

by Sangfor

CVEs (5)

  • CVE-2023-30806CriOct 10, 2023
    risk 0.69cvss 9.8epss 0.66

    The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /cgi-bin/login.cgi endpoint. This…

  • CVE-2023-30805CriOct 10, 2023
    risk 0.69cvss 9.8epss 0.66

    The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /LogInOut.php endpoint. This is…

  • CVE-2023-30803CriOct 10, 2023
    risk 0.65cvss 9.8epss 0.18

    The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can bypass authentication and access administrative functionality by sending HTTP requests using a crafted Y-forwarded-for…

  • CVE-2023-30802MedOct 10, 2023
    risk 0.35cvss 5.3epss 0.01

    The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to a source code disclosure vulnerability. A remote and unauthenticated attacker can obtain PHP source code by sending an HTTP request with an invalid Content-Length field.

  • CVE-2023-30804MedOct 10, 2023
    risk 0.33cvss 4.9epss 0.13

    The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authenticated file disclosure vulnerability. A remote and authenticated attacker can read arbitrary system files using the svpn_html/loadfile.php endpoint. This issue is exploitable by a remote and…