An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewalls endpoint at /spcgi.cgi allows information disclosure of memory contents to be achieved by an authenticated user. Essentially, uninitialized data can be retrieved via an approach in which a sessionid is obtained but not used.
The product uses or accesses a resource that has not been initialized.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Unified_threat_management | Securepoint | 12.2.3.1 (including) | 12.2.5.1 (excluding) |