CVSS v3
7.5
HIGH
EPSS Score
87.8%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an invalid authentication attempt. This can afterwards be used to bypass the device's authentication and get access to the administrative interface.
An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an invalid authentication attempt. This can afterwards be used to bypass the device's authentication and get access to the administrative interface.
Active exploitation of CVE-2023-22620 has not been confirmed. The EPSS score is 87.8%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2023-22620 has a CVSS v3 base score of 7.5 (HIGH severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).