CVE-2024-2648
A vulnerability, which was classified as problematic, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected is an unknown function of the file /nac/naccheck.php. The manipulation of the argument username leads to improper neutralization of data within xpath expressions. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257286 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS probability
- 0.73%
- CWE
- CWE-643
- Published
- 2024-03-19
- Last modified
- 2026-03-13
Affected products
- Netentsec NS-ASG Application Security Gateway
Weakness type
Related vulnerabilities
- CVE-2026-9390 — XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup
- CVE-2026-44962 — Plesk contains an XPath injection vulnerability in the APS Application Catalog search...
- CVE-2026-40699 — BIG-IP Configuration utility vulnerability
- CVE-2026-24343 — Apache HertzBeat: Uncontrolled Resource Consumption via Crafted XPath Expressions
- CVE-2025-11844 — XPath Injection in Hugging Face Smolagents search_item_ctrl_f Function
- CVE-2025-20218 — Cisco Secure Firepower Management Center Software XPATH Injection Vulnerability
- CVE-2022-43840 — IBM Aspera Console XPath injection
- CVE-2024-39565 — Junos OS: J-Web: An unauthenticated, network-based attacker can perform XPATH injection attack against a device.