QID 730975
Date Published: 2023-12-07
QID 730975: Sangfor Next-Generation Application Firewall (NGAF) Multiple Vulnerabilities
Sangfor NGAF is fully integrated NGFW (Next-Generation Firewall) and WAF (Web Application Firewall) with an all-around protection from all threats powered by innovations such as Neural X and Engine Zero.
CVE-2023-30802: Source Code Disclosure Vulnerability
CVE-2023-30803: Authentication Bypass Vulnerability
CVE-2023-30804: File Disclosure Vulnerability
CVE-2023-30805: Command Injection Vulnerability
CVE-2023-30806: Command Injection Vulnerability
Affected Version:
CVE-2023-30802: AF8.0.7-AF8.0.17
CVE-2023-30803: AF8.0.7-AF8.0.17
CVE-2023-30804: AF5.4-AF8.0.17
CVE-2023-30805: AF7.0-AF8.0.17
CVE-2023-30806: AF8.0.7-AF8.0.17
This QID sends request to /svpn_html/loadfile.php directory to check for the vulnerability
A remote and unauthenticated attacker can bypass authentication and access administrative functionality by sending HTTP requests using a crafted Y-forwarded-for header.
CVEs related to QID 730975
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| sangfor |
|