CVE-2015-0932 describes an authentication bypass vulnerability in ANTlabs InnGate firmware, affecting various IG 3100, IG 3101, and InnGate 3.x E/G series devices. This flaw allows unauthenticated remote attackers to read or write arbitrary files via rsync sessions on TCP port 873. With a CVSS score of 10.0, this critical vulnerability poses a significant risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation in the KEV catalog or public exploit code like Metasploit/Nuclei/ExploitDB, it has garnered notable community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:antlabs:inngate_ig_3.00_e:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:antlabs:inngate_ig_3.01_e:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:antlabs:inngate_ig_3.02_e:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:antlabs:inngate_ig_3.10_e:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:antlabs:inngate_ig_3.10_g:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.