Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

NS-ASG Application Security Gateway — Vulnerabilities & Security Advisories 29

All 29 CVE vulnerabilities found in NS-ASG Application Security Gateway, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations (CWE) affecting the NS-ASG Application Security Gateway, provided by the vendor NSFOCUS. It aggregates vulnerability data specifically related to this application security gateway solution to assist security professionals in managing risk exposure. The content covers a comprehensive range of security flaws discovered in the product, including but not limited to injection attacks, cross-site scripting, authentication bypasses, and path traversal issues. The database spans from the product’s initial release through the most recent quarterly updates, ensuring that both legacy and modern versions are accounted for. Readers can use this resource to systematically track vendor advisories and monitor the publication timeline of new security notices. It also provides the necessary context to understand the root causes and mitigation strategies for specific weakness classes prevalent in web application firewalls. Furthermore, users can look up the complete vulnerability history for the NS-ASG Application Security Gateway to assess their current deployment’s exposure to known exploits. By centralizing this information, the page facilitates a deeper analysis of the product’s security posture over time. This approach allows administrators to prioritize patching efforts based on the severity and prevalence of identified issues. The aggregation aims to provide a clear, factual record of security incidents without speculation or promotional language. This transparency supports informed decision-making regarding infrastructure protection and compliance requirements. Ultimately, the page serves as a critical reference point for evaluating the ongoing security health of the NS-ASG platform against evolving threat landscapes.

Vendor: Netentsec

CVE IDTitleCVSSSeverityPublished
CVE-2024-6007 Netentsec NS-ASG Application Security Gateway deleteiscgwrouteconf.php sql injection CWE-89 6.3 Medium2024-06-15
CVE-2024-5773 Netentsec NS-ASG Application Security Gateway deletemacbind.php sql injection CWE-89 6.3 Medium2024-06-09
CVE-2024-5772 Netentsec NS-ASG Application Security Gateway deleteiscuser.php sql injection CWE-89 6.3 Medium2024-06-09
CVE-2024-5590 Netentsec NS-ASG Application Security Gateway JSON Content uploadiscuser.php sql injection CWE-89 6.3 Medium2024-06-03
CVE-2024-5589 Netentsec NS-ASG Application Security Gateway sql injection CWE-89 6.3 Medium2024-06-03
CVE-2024-3458 Netentsec NS-ASG Application Security Gateway add_ikev2.php sql injection CWE-89 6.3 Medium2024-04-08
CVE-2024-3457 Netentsec NS-ASG Application Security Gateway config_ISCGroupNoCache.php sql injection CWE-89 6.3 Medium2024-04-08
CVE-2024-3456 Netentsec NS-ASG Application Security Gateway config_Anticrack.php sql injection CWE-89 6.3 Medium2024-04-08
CVE-2024-3455 Netentsec NS-ASG Application Security Gateway add_postlogin.php sql injection CWE-89 6.3 Medium2024-04-08
CVE-2024-3041 Netentsec NS-ASG Application Security Gateway listloginfo.php sql injection CWE-89 6.3 Medium2024-03-28
CVE-2024-3040 Netentsec NS-ASG Application Security Gateway list_crl_conf sql injection CWE-89 6.3 Medium2024-03-28
CVE-2024-2649 Netentsec NS-ASG Application Security Gateway deleteonlineuser.php sql injection CWE-89 6.3 Medium2024-03-19
CVE-2024-2648 Netentsec NS-ASG Application Security Gateway naccheck.php xpath injection CWE-643 4.3 Medium2024-03-19
CVE-2024-2647 Netentsec NS-ASG Application Security Gateway singlelogin.php sql injection CWE-89 7.3 High2024-03-19
CVE-2024-2646 Netentsec NS-ASG Application Security Gateway sql injection CWE-89 6.3 Medium2024-03-19
CVE-2024-2645 Netentsec NS-ASG Application Security Gateway resetpwd.php xpath injection CWE-643 4.3 Medium2024-03-19
CVE-2024-2644 Netentsec NS-ASG Application Security Gateway addfirewall.php sql injection CWE-89 6.3 Medium2024-03-19
CVE-2024-2330 Netentsec NS-ASG Application Security Gateway index.php sql injection CWE-89 6.3 Medium2024-03-09
CVE-2024-2329 Netentsec NS-ASG Application Security Gateway sql injection CWE-89 6.3 Medium2024-03-09
CVE-2024-2022 Netentsec NS-ASG Application Security Gateway list_ipAddressPolicy.php sql injection CWE-89 6.3 Medium2024-03-01
CVE-2024-2021 Netentsec NS-ASG Application Security Gateway list_localuser.php sql injection CWE-89 6.3 Medium2024-02-29
CVE-2023-7161 Netentsec NS-ASG Application Security Gateway Login sql injection CWE-89 7.3 High2023-12-29
CVE-2023-7094 Netentsec NS-ASG Application Security Gateway nsasg6.0.tgz information disclosure CWE-200 5.3 Medium2023-12-25
CVE-2023-6903 Netentsec NS-ASG Application Security Gateway sql injection CWE-89 7.3 High2023-12-17
CVE-2023-5826 Netentsec NS-ASG Application Security Gateway list_onlineuser.php sql injection CWE-89 5.5 Medium2023-10-27
CVE-2023-5785 Netentsec NS-ASG Application Security Gateway addaddress_interpret.php sql injection CWE-89 5.5 Medium2023-10-26
CVE-2023-5784 Netentsec NS-ASG Application Security Gateway uploadfirewall.php sql injection CWE-89 5.5 Medium2023-10-26
CVE-2023-5700 Netentsec NS-ASG Application Security Gateway uploadiscgwrouteconf.php sql injection CWE-89 5.5 Medium2023-10-22
CVE-2023-5681 Netentsec NS-ASG Application Security Gateway list_addr_fwresource_ip.php sql injection CWE-89 4.7 Medium2023-10-20

All 29 known CVE vulnerabilities affecting NS-ASG Application Security Gateway with full Chinese analysis, references, and POCs where available.