← Back to browse · API

CVE-2023-30803

Severity
CRITICAL
CVSS
9.8
EPSS
0.18206
Risk score
45.57
CISA KEV
No
PoC
No
Published
2023-10-10
Modified
2025-11-28
First seen
2026-08-07
Aliases
EUVD-2023-35163, GHSA-RCH9-592X-RRW8
Products
Sangfor:Net-Gen Application Firewall 8.0.17
Sources
euvd EUVD-2023-35163

Description

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can bypass authentication and access administrative functionality by sending HTTP requests using a crafted Y-forwarded-for header.

References