CVE-2023-22897

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/04/2023
Last modified:
10/02/2025

Description

An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows information disclosure of memory contents to be achieved by an authenticated user. Essentially, uninitialized data can be retrieved via an approach in which a sessionid is obtained but not used.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:securepoint:unified_threat_management:*:*:*:*:*:*:*:* 12.2.3.1 (including) 12.2.5.1 (excluding)