Search

Find a vulnerability

Search criteria

    1 vulnerability found for genian_nac by genians

    CVE-2023-40254 (GCVE-0-2023-40254)

    Vulnerability from cvelistv5 – Published: 2023-08-11 06:08 – Updated: 2024-10-10 14:58
    VLAI
    Summary
    Download of Code Without Integrity Check vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Malicious Software Update.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Genian NAC V5.0: from V5.0.0 through V5.0.42 (Revision 117460); Genian NAC Suite V5.0: from V5.0.0 through V5.0.54; Genian ZTNA: from V6.0.0 through V6.0.15.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-10 14:54 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Impacted products
    Vendor Product Version
    Genians Genian NAC V4.0 Affected: V4.0.0 , ≤ V4.0.155 (custom)
    Create a notification for this product.
    Genians Genian NAC V5.0 Affected: V5.0.0 , ≤ V5.0.42 (Revision 117460) (custom)
    Create a notification for this product.
    Genians Genian NAC Suite V5.0 Affected: V5.0.0 , ≤ V5.0.54 (custom)
    Create a notification for this product.
    Genians Genian ZTNA Affected: V6.0.0 , ≤ V6.0.15 (custom)
    Create a notification for this product.
    genians genian_nac Affected: 4.0.0 , ≤ 4.0.155 (custom)
    Affected: 5.0.0 , ≤ 5.0.42 (custom)
    Affected: 5.0.0 , ≤ 5.0.54 (custom)
    Affected: 6.0.0 , ≤ 6.0.15 (custom)
        cpe:2.3:a:genians:genian_nac:4.0.0:*:*:*:-:*:*:*
    Create a notification for this product.
    Date Public
    2023-07-31 05:16
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T18:24:55.811Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://docs.genians.com/nac/5.0/release/ko/advisories/GN-SA-2023-001.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:genians:genian_nac:4.0.0:*:*:*:-:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "genian_nac",
                "vendor": "genians",
                "versions": [
                  {
                    "lessThanOrEqual": "4.0.155",
                    "status": "affected",
                    "version": "4.0.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "5.0.42",
                    "status": "affected",
                    "version": "5.0.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "5.0.54",
                    "status": "affected",
                    "version": "5.0.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "6.0.15",
                    "status": "affected",
                    "version": "6.0.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-40254",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-10T14:54:36.654999Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-10T14:58:22.730Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "Genian NAC V4.0",
              "vendor": "Genians",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "V4.0.156",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "V4.0.155",
                  "status": "affected",
                  "version": "V4.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Genian NAC V5.0",
              "vendor": "Genians",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "V5.0.42 (Revision 117461)",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "V5.0.42 (Revision 117460)",
                  "status": "affected",
                  "version": "V5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Genian NAC Suite V5.0",
              "vendor": "Genians",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "V5.0.55",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "V5.0.54",
                  "status": "affected",
                  "version": "V5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Genian ZTNA",
              "vendor": "Genians",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "V6.0.16",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "V6.0.15",
                  "status": "affected",
                  "version": "V6.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2023-07-31T05:16:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Download of Code Without Integrity Check vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Malicious Software Update.\u003cp\u003eThis issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Genian NAC V5.0: from V5.0.0 through V5.0.42 (Revision 117460); Genian NAC Suite V5.0: from V5.0.0 through V5.0.54; Genian ZTNA: from V6.0.0 through V6.0.15.\u003c/p\u003e"
                }
              ],
              "value": "Download of Code Without Integrity Check vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Malicious Software Update.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Genian NAC V5.0: from V5.0.0 through V5.0.42 (Revision 117460); Genian NAC Suite V5.0: from V5.0.0 through V5.0.54; Genian ZTNA: from V6.0.0 through V6.0.15.\n\n"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-186",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-186 Malicious Software Update"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-26T05:26:24.058Z",
            "orgId": "cdd7a122-0fae-4202-8d86-14efbacc2863",
            "shortName": "krcert"
          },
          "references": [
            {
              "url": "https://docs.genians.com/nac/5.0/release/ko/advisories/GN-SA-2023-001.html"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cdd7a122-0fae-4202-8d86-14efbacc2863",
        "assignerShortName": "krcert",
        "cveId": "CVE-2023-40254",
        "datePublished": "2023-08-11T06:08:19.709Z",
        "dateReserved": "2023-08-11T01:54:13.646Z",
        "dateUpdated": "2024-10-10T14:58:22.730Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }