Netentsec develops application security gateway products, a focused but prominent portfolio that serves as a critical control point for web traffic and application access. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes across its flagship NS-ASG appliance and firmware, concentrating in injection-class weaknesses—SQL injection, code injection, XPath injection, and XML injection—that reflect the parser and query-evaluation demands of a gateway positioned to inspect and validate application-layer traffic. These weakness classes are characteristic of products that must handle untrusted input at scale and represent a durable structural risk for this product category. Defenders should treat Netentsec gateway advisories as high-priority and verify remediation across deployed instances, particularly where the appliance sits between users and sensitive applications; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netentsec over time
Signals from CVEs in this vendor scope (48 CVEs).
48 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2330CRITICAL A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This affects an unknown part of the file /protocol/index.php. Th | Mar 9, 2024 | 9.8 | 46 | NO | YES |
CVE-2024-2022CRITICAL A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the | Mar 1, 2024 | 9.8 | 36 | NO | NO |
CVE-2024-2021CRITICAL A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. Affected is an unknown function of the file /admin/list_localuse | Mar 1, 2024 | 9.8 | 32 | NO | NO |
CVE-2023-30242CRITICAL NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php. | May 5, 2023 | 9.8 | 32 | NO | NO |
CVE-2024-3456CRITICAL A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /adm | Apr 8, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-2644CRITICAL A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /pro | Mar 19, 2024 | 9.8 | 30 | NO | NO |
CVE-2023-6903CRITICAL A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3.1. This affects an unknown part of the file /admin/singlelogin.php?submit | Dec 17, 2023 | 9.8 | 30 | NO | NO |
CVE-2024-3040CRITICAL A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /admin/list_crl_conf. Th | Mar 28, 2024 | 9.8 | 28 | NO | NO |
CVE-2023-5700CRITICAL A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected is an unknown function of the file /protocol/iscgwtunnel | Oct 23, 2023 | 9.8 | 28 | NO | NO |
CVE-2024-3458CRITICAL A vulnerability classified as critical was found in Netentsec NS-ASG Application Security Gateway 6.3. This vulnerability affects unknown code of the file /admin/add_ikev2.php. The | Apr 8, 2024 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (48 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netentsec.
Media articles that mention a CVE ID that affects a product developed by Netentsec — matched by CVE ID, not by vendor name.