CVE-2019-9632
23Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 24%
exploitation probability
24%top 2% of all CVEs
observed exploitation
nono source reports it
ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.
Affected products
n/a · n/a