CVE-2024-5050

A vulnerability, which was classified as critical, was found in Wangshen SecGate 3600 up to 20240516. This affects an unknown part of the file /?g=log_import_save. The manipulation of the argument reqfile leads to unrestricted upload. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-264747.
Configurations

No configuration.

History

21 Nov 2024, 09:46

Type Values Removed Values Added
References () https://github.com/h0e4a0r1t/h0e4a0r1t.github.io/blob/master/2024/s%40%23NGfP%7B4%5Et(%7C%5Dd9/Wangshen%20SecGata%203600%20Firewall%20log_import_save%20arbitrary%20file%20upload%20vulnerability.pdf - () https://github.com/h0e4a0r1t/h0e4a0r1t.github.io/blob/master/2024/s%40%23NGfP%7B4%5Et(%7C%5Dd9/Wangshen%20SecGata%203600%20Firewall%20log_import_save%20arbitrary%20file%20upload%20vulnerability.pdf -
References () https://vuldb.com/?ctiid.264747 - () https://vuldb.com/?ctiid.264747 -
References () https://vuldb.com/?id.264747 - () https://vuldb.com/?id.264747 -
References () https://vuldb.com/?submit.335968 - () https://vuldb.com/?submit.335968 -

04 Jun 2024, 19:20

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad fue encontrada en Wangshen SecGate 3600 hasta 20240516 y clasificada como crítica. Una parte desconocida del archivo /?g=log_import_save es afectada por esta vulnerabilidad. La manipulación del argumento reqfile conduce a una carga sin restricciones. Es posible iniciar el ataque de forma remota. El identificador asociado de esta vulnerabilidad es VDB-264747.

17 May 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-17 14:15

Updated : 2024-11-21 09:46


NVD link : CVE-2024-5050

Mitre link : CVE-2024-5050

CVE.ORG link : CVE-2024-5050


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type