Vulnerability Details CVE-2023-22897
An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows information disclosure of memory contents to be achieved by an authenticated user. Essentially, uninitialized data can be retrieved via an approach in which a sessionid is obtained but not used.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.888
EPSS Ranking 99.5%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2023-22897
-
cpe:2.3:o:securepoint:unified_threat_management:12.2.3.1
-
cpe:2.3:o:securepoint:unified_threat_management:12.2.3.2
-
cpe:2.3:o:securepoint:unified_threat_management:12.2.3.3
-
cpe:2.3:o:securepoint:unified_threat_management:12.2.3.4
-
cpe:2.3:o:securepoint:unified_threat_management:12.2.4
-
cpe:2.3:o:securepoint:unified_threat_management:12.2.4.1
-
cpe:2.3:o:securepoint:unified_threat_management:12.2.5