CVE-2023-40254

Download of Code Without Integrity Check vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Malicious Software Update.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Genian NAC V5.0: from V5.0.0 through V5.0.42 (Revision 117460); Genian NAC Suite V5.0: from V5.0.0 through V5.0.54; Genian ZTNA: from V6.0.0 through V6.0.15.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:genians:genian_nac:*:*:*:*:-:*:*:*
cpe:2.3:a:genians:genian_nac:*:*:*:*:-:*:*:*
cpe:2.3:a:genians:genian_nac:5.0.42:-:*:*:lts:*:*:*
cpe:2.3:a:genians:genian_nac:5.0.42:revision_117460:*:*:lts:*:*:*
cpe:2.3:a:genians:genian_ztna:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:19

Type Values Removed Values Added
References () https://docs.genians.com/nac/5.0/release/ko/advisories/GN-SA-2023-001.html - () https://docs.genians.com/nac/5.0/release/ko/advisories/GN-SA-2023-001.html -
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 7.5
Summary
  • (es) La vulnerabilidad de descarga de código sin comprobación de integridad en Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA permite la actualización de software malicioso. Este problema afecta a Genian NAC V4.0: de V4.0.0 a V4.0.155; Genian NAC V5.0: de V5.0.0 a V5.0.42 (Revisión 117460); Genian NAC Suite V5.0: de V5.0.0 a V5.0.54; Genian ZTNA: de V6.0.0 a V6.0.15.

Information

Published : 2023-08-11 07:15

Updated : 2024-11-21 08:19


NVD link : CVE-2023-40254

Mitre link : CVE-2023-40254

CVE.ORG link : CVE-2023-40254


JSON object : View

Products Affected

genians

  • genian_nac
  • genian_ztna
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CWE-494

Download of Code Without Integrity Check