S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-22620 Scanner

CVE-2023-22620 scanner - Information Disclosure vulnerability in SecurePoint UTM

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-22620
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required · user interaction needed.

An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an invalid authentication attempt. This can afterwards be used to bypass the device's authentication and get access to the administrative interface.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

SecurePoint UTM is a firewall solution designed to protect networks and users from potential cyber threats. This system's purpose is to help businesses maintain their digital security by providing anti-virus, anti-spam, web-filtering, content inspection, and intrusion detection/prevention capabilities in one package. It's an all-in-one security solution ideal for mid-sized businesses and enterprises. 

CVE-2023-22620 is a vulnerability that was recently discovered in SecurePoint UTM that poses a major risk to network security. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an invalid authentication attempt. This information can be used to bypass the device's authentication, thus gaining access to the administrative interface. Hackers could easily exploit this vulnerability and gain access to various confidential company data. This bug was discovered in versions of SecurePoint UTM released prior to 12.2.5.1. 

When this vulnerability is exploited, it can cause a variety of serious issues. In extreme cases, hackers can gain access to the system and steal sensitive information such as credit card details, passwords, and other important financial and personal information. This could lead to identity theft, financial loss, legal problems, and a damaged company reputation. 

Thanks to the pro features of the s4e.io platform, businesses can quickly identify vulnerabilities in their digital assets. This platform provides users with detailed reports on their digital security posture, along with recommendations to help improve it. By utilizing this platform, businesses can be confident that their networks are secure from potential cyber threats. With its user-friendly interface and ease of use, it makes conducting assessments and identifying vulnerabilities an easy and hassle-free process.

 

REFERENCES

Solution Advice

It is essential to protect businesses against these kinds of vulnerabilities. Some precautions that can be taken to safeguard against CVE-2023-22620 include:

  • Upgrading to the latest version of SecurePoint UTM, which has addressed the vulnerability.
  • Restricting access to the /spcgi.cgi endpoint to authorized users only.
  • Implementing strict company security policies around password use and authentication protocols.
  • Regularly conducting vulnerability assessments and security audits to identify potential flaws.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.