Unrestricted File Upload Vulnerability in Wangshen SecGate 3600
CVE-2024-3444
What is CVE-2024-3444?
A significant security vulnerability has been discovered in the Wangshen SecGate 3600 firewall, specifically within the file processing endpoint /?g=net_pro_keyword_import_save. This vulnerability enables unauthorized users to upload arbitrary files by exploiting the manipulation of the 'reqfile' parameter. Due to its nature, the attack can be executed remotely, posing a serious threat to the integrity and confidentiality of systems leveraging this product. Security professionals and users of Wangshen SecGate 3600 are urged to review their systems for this vulnerability and implement necessary security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SecGate 3600 20240408
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
