PoC Index

CVE-2018-5403

HIGH 8.1EPSS 2.4%

Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basic authentication passwords, the GW may be vulnerable to RCE through specially crafted requests, from the web access management interface.

CVSS v3.0
8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
2.41% chance of exploitation in the next 30 days, 83th percentile
Published
2019-01-10
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related