CVE-2019-9632
30Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 40%
exploitation probability
40%top 1% of all CVEs
observed exploitation
nono source reports it
ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.
Affected products
n/a · n/a