Impact
Improper input validation allows attackers to inject arbitrary SQL and bypass authentication checks, enabling unauthorized data access and modification. The vulnerability can lead to full compromise of the data store, exposing sensitive user information and potentially enabling further lateral movement within the network.
Affected Systems
Affects Genians Genian NAC versions 4.0.0 through 4.0.174 (revision 150340) and 5.0.0 through 5.0.87 (revisions 150331‑150328). It also impacts Genians Genian ZTNA versions 6.0.0 through 6.0.47 (revisions 150337‑150333).
Risk and Exploitability
The CVSS score is 8.7, indicating high severity. The EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation yet; however, the attack vector likely involves data query endpoints that accept user input, making it the responsibility of administrators to apply patches promptly.
OpenCVE Enrichment