ID

VAR-202408-2999


TITLE

There is an arbitrary file read vulnerability in the NetGuard Trusted Boundary Integrated Security Gateway System of Beijing NetGuard Nebula Information Technology Co., Ltd.

Trust: 0.6

sources: CNVD: CNVD-2024-34072

DESCRIPTION

Beijing NetGuard Nebula Information Technology Co., Ltd. is a leading enterprise in the domestic information security industry, specializing in the research and development, production and sales of information security products. Beijing NetGuard Nebula Information Technology Co., Ltd. NetGuard's trusted boundary integrated security gateway system has an arbitrary file read vulnerability, which can be exploited by attackers to obtain sensitive information.

Trust: 0.6

sources: CNVD: CNVD-2024-34072

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2024-34072

AFFECTED PRODUCTS

vendor:netguard nebula informationmodel:trusted boundary integrated security gateway systemscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2024-34072

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2024-34072
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2024-34072
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2024-34072

PATCH

title:Patch for There is an arbitrary file read vulnerability in the NetGuard Trusted Boundary Integrated Security Gateway System of Beijing NetGuard Nebula Information Technology Co., Ltd.url:https://www.cnvd.org.cn/patchInfo/show/573966

Trust: 0.6

sources: CNVD: CNVD-2024-34072

EXTERNAL IDS

db:CNVDid:CNVD-2024-34072

Trust: 0.6

sources: CNVD: CNVD-2024-34072

SOURCES

db:CNVDid:CNVD-2024-34072

LAST UPDATE DATE

2024-11-03T22:38:53.348000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2024-34072date:2024-07-31T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2024-34072date:2024-08-25T00:00:00