TGViewer
Netlas.io Netlas.io @netlas · 2.34K subscribers
Post #57 337
SecurePoint Authentication vulnerability

"If you sit on the river bank for a long time, you can see how the sessionId of the administrator floats by"
- Sun Tzu.

CVE-2023-22620 requires a bit of patience as the attacker has to wait for the administrator to log in, catch his sessionId, and brute force the User-Agent. However, after that, this will give full control over the root panel of the firewall.

Look at Netlas.io:
👉🏻 Dork: http.favicon.hash_sha256:ebaaed8ab7c21856f888117edaf342f6bc10335106ed907f95787b69878d9d9e
👉🏻 Search: nt.ls/k9W35

Original article: https://www.rcesecurity.com/2023/04/securepwn-part-1-bypassing-securepoint-utms-authentication-cve-2023-22620/
  • 🔥 4
  • ❤ 1
  • 👾 1
More from @netlas
  1. Oct 7, 2026CVE-2026-106445 & CVE-2026-106446: Two RCE flaws in Handlebars.js, up to 9.8 rating ‍🔥 Tw…
  2. Oct 6, 2026🎯 Netlas v1.10 Track changes in your attack surface with the new private scan comparison.…
  3. Oct 6, 2026CVE-2026-88779: DoS vulnerability in Citrix NetScaler ADC & Gateway, 8.7 rating ‍🔥 A rece…
  4. Oct 5, 2026CVE-2026-96940: EoP vulnerability in MS Exchange Server, 8.8 rating ‍🔥 Microsoft has upda…
  5. Oct 2, 2026CVE-2026-63292 and others: Multiple vulnerabilities in Apache HTTP Server, up to 9.8 ratin…
  6. Sep 29, 2026CVE-2026-88771 & CVE-2026-88772: RCE and/or DoS in Citrix NetScaler ADC and NetScaler Gate…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →