SQL Injection vulnerability in Netcome NS-ASG Application Security Gateway v.6.3.1 allows a local attacker to execute arbitrary code and obtain sensitive information via a crafted script to the loginid parameter of the /singlelogin.php component.
History

Tue, 17 Jun 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Netentsec
Netentsec application Security Gateway Firmware
Netentsec ns-asg
CPEs cpe:2.3:h:netentsec:ns-asg:-:*:*:*:*:*:*:*
cpe:2.3:o:netentsec:application_security_gateway_firmware:6.3.1:*:*:*:*:*:*:*
Vendors & Products Netentsec
Netentsec application Security Gateway Firmware
Netentsec ns-asg

Wed, 28 Aug 2024 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-03-21T00:00:00

Updated: 2024-08-28T14:28:06.875Z

Reserved: 2024-03-08T00:00:00

Link: CVE-2024-28521

cve-icon Vulnrichment

Updated: 2024-08-02T00:56:57.864Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-21T22:15:12.457

Modified: 2025-06-17T14:45:13.120

Link: CVE-2024-28521

cve-icon Redhat

No data.