SecurePoint Authentication vulnerability
"If you sit on the river bank for a long time, you can see how the sessionId of the administrator floats by"
- Sun Tzu.
CVE-2023-22620 requires a bit of patience as the attacker has to wait for the administrator to log in, catch his sessionId, and brute force the User-Agent. However, after that, this will give full control over the root panel of the firewall.
Look at Netlas.io:
👉🏻 Dork: http.favicon.hash_sha256:ebaaed8ab7c21856f888117edaf342f6bc10335106ed907f95787b69878d9d9e
👉🏻 Search: nt.ls/k9W35
Original article: https://www.rcesecurity.com/2023/04/securepwn-part-1-bypassing-securepoint-utms-authentication-cve-2023-22620/
Post #57
337

- 🔥 4
- ❤ 1
- 👾 1