CVE Database
/

CVE-2023-40251

Back to search

CVE-2023-40251

Published: Aug 17, 2023

Modified: Oct 1, 2024

PUBLISHED

CVSS v3.1

5.2

MEDIUM

Description

Missing Encryption of Sensitive Data vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Man in the Middle Attack.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Genian NAC V5.0: from V5.0.0 through V5.0.42 (Revision 117460); Genian NAC Suite V5.0: from V5.0.0 through V5.0.54; Genian ZTNA: from V6.0.0 through V6.0.15.

VendorProductVersions

Genians

Genian NAC V4.0

affected
V4.0.0 - <= V4.0.155

Genians

Genian NAC V5.0

affected
V5.0.0 - <= V5.0.42 (Revision 117460)

Genians

Genian NAC Suite V5.0

affected
V5.0.0 - <= V5.0.54

Genians

Genian ZTNA

affected
V6.0.0 - <= V6.0.15

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

Low

User Interaction

Required

Scope

Unchanged

Confidentiality

High

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now