Low Privileged Remote Attackers Can Cause Denial of Service (DoS) Through Configuration Changes of the Firewall Service
CVE-2024-43390

8.1HIGH

Key Information:

Vendor
CVE Published:
10 September 2024

Summary

A vulnerability exists in the Network Security Appliance from ABC Corp that allows a low privileged remote attacker to alter firewall configurations. By exploiting the FW_NAT.IN_IP environment variable, the attacker can manipulate critical settings such as packet forwarding or Network Address Translation (NAT). This manipulation may lead to potential denial of service, disrupting normal operations and affecting network integrity. Immediate remediation is essential to safeguard against unauthorized access and ensure the continued reliability of the affected firewall services.

Affected Version(s)

FL MGUARD 2102 0 < 10.4.1

FL MGUARD 2105 0 < 10.4.1

FL MGUARD 4102 PCI 0 < 10.4.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrea Palanca
Nozomi Networks Security Research Team
.