CVE-2017-17023
Summary
| CVE | CVE-2017-17023 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-09 18:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | The Sophos UTM VPN endpoint interacts with client software provided by NPC Engineering (www.ncp-e.com). The affected client software, "Sophos IPSec Client" 11.04 is a rebranded version of NCP "Secure Entry Client" 10.11 r32792. A vulnerability in the software update feature of the VPN client allows a man-in-the-middle (MITM) or man-on-the-side (MOTS) attacker to execute arbitrary, malicious software on a target user's computer. This is related to SIC_V11.04-64.exe (Sophos), NCP_EntryCl_Windows_x86_1004_31799.exe (NCP), and ncpmon.exe (both Sophos and NCP). The vulnerability exists because: (1) the VPN client requests update metadata over an insecure HTTP connection; and (2) the client software does not check if the software update is signed before running it. |
Risk And Classification
Problem Types: CWE-345
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ncp-e | Ncp Secure Entry Client | 10.11 | 32792 | All | All |
| Application | Ncp-e | Ncp Secure Entry Client | 10.11 | 32792 | All | All |
| Application | Sophos | Ipsec Client | 11.04 | All | All | All |
| Application | Sophos | Ipsec Client | 11.04 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Download VPN Software Clients | MISC | www.ncp-e.com | Vendor Advisory |
| 404 Not Found | CONFIRM | www.ncp-e.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.