CVE Database
/

CVE-2023-40254

Back to search

CVE-2023-40254

Published: Aug 11, 2023

Modified: Oct 10, 2024

PUBLISHED

CVSS v3.1

7.5

HIGH

Description

Download of Code Without Integrity Check vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Malicious Software Update.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Genian NAC V5.0: from V5.0.0 through V5.0.42 (Revision 117460); Genian NAC Suite V5.0: from V5.0.0 through V5.0.54; Genian ZTNA: from V6.0.0 through V6.0.15.

VendorProductVersions

Genians

Genian NAC V4.0

affected
V4.0.0 - <= V4.0.155

Genians

Genian NAC V5.0

affected
V5.0.0 - <= V5.0.42 (Revision 117460)

Genians

Genian NAC Suite V5.0

affected
V5.0.0 - <= V5.0.54

Genians

Genian ZTNA

affected
V6.0.0 - <= V6.0.15

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

High

Privileges Required

High

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now