S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-22897 Scanner

CVE-2023-22897 scanner - Information Disclosure vulnerability in SecurePoint UTM

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-22897
6.5
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.

An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows information disclosure of memory contents to be achieved by an authenticated user. Essentially, uninitialized data can be retrieved via an approach in which a sessionid is obtained but not used.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

SecurePoint UTM is a firewall that is commonly used to protect digital assets and networks from cyber threats such as malware, viruses, and other forms of unauthorized access. This product is designed to provide comprehensive protection by monitoring and filtering incoming and outgoing traffic, as well as detecting and blocking suspicious activities in real-time. It is a critical tool in ensuring the security of digital assets against cyberattacks.

CVE-2023-22897 is a vulnerability that has been detected in SecurePoint UTM software before version 12.2.5.1. This vulnerability specifically relates to the firewall's endpoint at /spcgi.cgi, which allows unauthorized individuals to gain access to memory contents. By exploiting this vulnerability, attackers could potentially steal sensitive information such as login credentials, session tokens, and other data that can be used to compromise digital assets.

When exploited, this vulnerability can lead to a range of negative consequences. For example, attackers can use the stolen data to gain unauthorized access to systems, steal intellectual property, or cause network disruptions. It can also result in the loss or theft of sensitive data, which can result in reputational damage, legal issues, or financial losses.

In conclusion, the s4e.io platform features pro tools that enable individuals to quickly and easily assess vulnerabilities in their digital assets. With these tools, users can identify potential weaknesses and take preventative measures to enhance security. By staying informed and vigilant, individuals can prevent cyberattacks and effectively protect their digital assets from unauthorized access and other malicious activities.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users should take the following precautions:

  • Install the latest software updates and patches for SecurePoint UTM
  • Restrict access to the /spcgi.cgi endpoint and other sensitive areas of the firewall
  • Deploy advanced security tools such as intrusion detection/prevention systems (IDS/IPS), antivirus software, and firewalls to detect and block malicious traffic
  • Implement strong authentication mechanisms such as multi-factor authentication (MFA) to secure user logins and other sensitive data
  • Conduct regular security audits and vulnerability assessments to identify and address potential security gaps

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.