Symantec Clientless VPN Gateway 4400 Lets Remote Authentication Users Modify Other User Credentials
|
|
SecurityTracker Alert ID: 1010918
|
|
SecurityTracker URL: http://securitytracker.com/id?1010918
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Aug 10 2004
|
Impact: Disclosure of authentication information, Disclosure of user information, Execution of arbitrary code via network, Modification of user information, Not specified
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): Version 5.0, Model 4000
|
Description: Several vulnerabilities were reported in the Symantec Clientless VPN Gateway 4400 Series. A remote authenticated user can modify another user's authentication information.
Symantec reported that there are "various security vulnerabilities" in the ActiveX file browser and the HTML file browser. No further
details were provided.
It is also reported that the end user user-interface (UI) contains cross-site scripting flaws.
It is
also reported that the end user UI allows a remote authenticated user to change a target user's single signon information, including
the username and password.
|
Impact: A remote authenticated user can change a target user's single signon information, including the username and password.
A remote
user can access the target user's cookies (including authentication cookies), if any, associated with the VPN Gateway, access data
recently submitted by the target user via web form to the site, or take actions on the site acting as the target user.
The impact
of several of the vulnerabilities was not disclosed.
|
Solution: The vendor has released a fix (Hotfix SCVG5-20040806-00), described at:
ftp://ftp.symantec.com/public/english_us_canada/products/sym_clientless_vpn/sym_clientless_vpn_5/updates/hf3-readme.txt
|
Vendor URL: enterprisesecurity.symantec.com/products/products.cfm?ProductID=342&EID=0 (Links to External Site)
|
Cause: Access control error, Input validation error, Not specified
|
|
Message History:
None.
|
Source Message Contents
|
Date: Aug 10, 2004
Subject: Symantec Clientless VPN Gateway 5.0 - Model 4400 Series
|
ftp://ftp.symantec.com/public/english_us_canada/products/sym_clientless_vpn/
sym_clientless_vpn_5/updates/hf3-readme.txt
> Hotfix: SCVG5-20040806-00
> ActiveX file browser:
> - Fixed various security vulnerabilities.
> End user UI:
> - Fixed various XSS security vulnerabilities.
> - Fixed security hole where user A can change user B's single signon
> information (username and password included) through the end user UI.
> HTML file browser:
> - Fixed various security vulnerabilities.
|
|