CVE-2023-22897: Securepoint UTM - Leaking Remote Memory Contents
PoC2025-08-01
影响软件
Securepoint UTM
关联产品
漏洞描述
An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows information disclosure of memory contents to be achieved by an authenticated user. Essentially, uninitialized data can be retrieved via an approach in which a sessionid is obtained but not used.
PoC / 利用代码
登录后可查看 PoC 内容