CVE Vulnerabilities

CVE-2023-40253

Improper Authentication

Published: Aug 11, 2023 | Modified: Aug 29, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper Authentication vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Authentication Abuse.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Genian NAC V5.0: from V5.0.0 through V5.0.42 (Revision 117460); Genian NAC Suite V5.0: from V5.0.0 through V5.0.54; Genian ZTNA: from V6.0.0 through V6.0.15.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Genian_nac Genians 4.0.0 (including) 4.0.156 (excluding)
Genian_nac Genians 5.0.0 (including) 5.0.55 (excluding)
Genian_nac Genians 5.0.42 (including) 5.0.42 (including)
Genian_nac Genians 5.0.42-revision_117460 (including) 5.0.42-revision_117460 (including)
Genian_ztna Genians 6.0.0 (including) 6.0.16 (excluding)

Potential Mitigations

References