CVE-2023-40254

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Aug 11, 2023
Updated: Oct 26, 2023
CWE ID 89
CWE ID 494

Summary

CVE-2023-40254 is a vulnerability affecting multiple Genians products: Genian NAC V4.0 (from V4.0.0 through V4.0.155), Genian NAC V5.0 (from V5.0.0 through V5.0.42, Revision 117460), Genian NAC Suite V5.0 (from V5.0.0 through V5.0.54), and Genian ZTNA (from V6.0.0 through V6.0.15). This issue involves a Download of Code Without Integrity Check, enabling malicious software updates. An attacker who successfully exploits this vulnerability can install unauthorized software, potentially compromising the targeted system. Users of the affected Genians products are recommended to update to the latest versions as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share