ID

VAR-202110-1915


TITLE

Leadsec ACM, NetGuard's online behavior management system, has a SQL injection vulnerability

Trust: 0.6

sources: CNVD: CNVD-2021-67310

DESCRIPTION

Beijing Wangyu Xingyun Information Technology Co., Ltd. was renamed from Lenovo Wangyu Technology (Beijing) Co., Ltd. Its business covers network boundary security protection, application and data security protection, network-wide security risk management, professional security solutions, and professional security services, etc. Multiple directions. Leadsec ACM, the NetGuard online behavior management system, has a SQL injection vulnerability. Attackers can use the vulnerability to obtain sensitive information in the database.

Trust: 0.6

sources: CNVD: CNVD-2021-67310

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-67310

AFFECTED PRODUCTS

vendor:wangyu nebula informationmodel:internet behavior management system leadsec acmscope:ltversion:20150824

Trust: 0.6

sources: CNVD: CNVD-2021-67310

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2021-67310
value: HIGH

Trust: 0.6

CNVD: CNVD-2021-67310
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2021-67310

PATCH

title:Patch for Leadsec ACM, NetGuard's online behavior management system, has a SQL injection vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/288811

Trust: 0.6

sources: CNVD: CNVD-2021-67310

EXTERNAL IDS

db:CNVDid:CNVD-2021-67310

Trust: 0.6

sources: CNVD: CNVD-2021-67310

SOURCES

db:CNVDid:CNVD-2021-67310

LAST UPDATE DATE

2022-05-04T09:32:18.681000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-67310date:2021-10-26T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-67310date:2021-10-16T00:00:00