9.8
CVE-2023-30803
- EPSS 18.21%
- Veröffentlicht 10.10.2023 15:15:09
- Zuletzt bearbeitet 28.11.2025 16:15:50
- Quelle disclosure@vulncheck.com
- CVE-Watchlists
- Unerledigt
Sangfor Next-Gen Application Firewall Authentication Bypass
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can bypass authentication and access administrative functionality by sending HTTP requests using a crafted Y-forwarded-for header.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sangfor ≫ Next-gen Application Firewall Version8.0.17
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 18.21% | 0.968 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| disclosure@vulncheck.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-290 Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
https://aws.amazon.com/marketplace/pp/prodview-uujwjffddxzp4
https://labs.watchtowr.com/yet-more-unauth-remote-command-execution-vulns-in-firewalls-sangfor-edition/
https://vulncheck.com/advisories/sangfor-ngaf-auth-bypass