{"id":"CVE-2023-30804","title":"The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authenticated file disclosure vulnerability","summary":"The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authenticated file disclosure vulnerability. A remote and authenticated attacker can read arbitrary system files using the svpn_html/loadfile.php endpoint. …","severity":"medium","cvss":4.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-22"],"vendor":"sangfor","product":"next-gen_application_firewall","affected":["next-gen_application_firewall = 8.0.17"],"published":"2023-10-10","updated":"2026-10-01","sourceUpdated":"2026-10-01T15:17:17.093","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-30804","references":[{"url":"https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/sangfor/sangfor-ngaf-lfi.yaml","label":"disclosure@vulncheck.com"},{"url":"https://labs.watchtowr.com/yet-more-unauth-remote-command-execution-vulns-in-firewalls-sangfor-edition/","label":"disclosure@vulncheck.com"},{"url":"https://vulncheck.com/advisories/sangfor-ngaf-auth-file-disclosure","label":"disclosure@vulncheck.com"},{"url":"https://aws.amazon.com/marketplace/pp/prodview-uujwjffddxzp4","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://labs.watchtowr.com/yet-more-unauth-remote-command-execution-vulns-in-firewalls-sangfor-edition/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://vulncheck.com/advisories/sangfor-ngaf-auth-file-disclosure","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2024-09-19T14:22:02.639064Z"},"epss":0.12816,"epssPercentile":0.96175,"ingestedAt":"2026-10-01T15:48:17.792Z","slug":"CVE-2023-30804","body":"## Overview\n\nThe Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authenticated file disclosure vulnerability. A remote and authenticated attacker can read arbitrary system files using the svpn_html/loadfile.php endpoint. This issue is exploitable by a remote and unauthenticated attacker when paired with CVE-2023-30803.\n\n## Affected\n\n- `next-gen_application_firewall = 8.0.17`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":27,"likelihood":2.6,"exploitation":12,"ransomware":0},"changes":[]}