CVE-2015-2849
Last modified
CVE-2015-2849 is a vulnerability of currently unknown severity. SQL injection vulnerability in main.ant in the ANTlabs InnGate firmware on IG 3100, InnGate 3.01 E, InnGate 3.10 E, InnGate 3.10 M, SG 4, and SSG 4 devices, when https is used, allows remote attackers to execute arbitrary SQL commands via the ppli parameter.. EPSS estimates a 1.35% chance of exploitation in the next 30 days.
Description
SQL injection vulnerability in main.ant in the ANTlabs InnGate firmware on IG 3100, InnGate 3.01 E, InnGate 3.10 E, InnGate 3.10 M, SG 4, and SSG 4 devices, when https is used, allows remote attackers to execute arbitrary SQL commands via the ppli parameter.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Antlabs | Inngate Ig 3.01 E | All versions |
| Antlabs | Inngate Ig 3.10 E | All versions |
| Antlabs | Inngate Ig 3.10 M | All versions |
| Antlabs | Inngate Ig 3100 | All versions |
| Antlabs | Inngate Sg 4 | All versions |
| Antlabs | Inngate Ssg 4 | All versions |
References
- http://www.kb.cert.org/vuls/id/485324Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/485324Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-2849?
How severe is CVE-2015-2849?
How do I fix CVE-2015-2849?
Are you affected by CVE-2015-2849?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
