Sygate Secure Enterprise Enforcer Unauthenticated Broadcast Request Bypass Vulnerability
BID:10908
Info
Sygate Secure Enterprise Enforcer Unauthenticated Broadcast Request Bypass Vulnerability
| Bugtraq ID: | 10908 |
| Class: | Design Error |
| CVE: |
CVE-2004-0593 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 10 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Discovery is credited to Corsaire <http://www.corsaire.com>. |
| Vulnerable: |
Sygate Secure Enterprise 3.5 Sygate Secure Enterprise 3.0 |
| Not Vulnerable: |
Sygate Secure Enterprise 4.0 Sygate Secure Enterprise 3.5 MR3 Sygate Secure Enterprise 3.5 MR1 |
Discussion
Sygate Secure Enterprise Enforcer Unauthenticated Broadcast Request Bypass Vulnerability
It is reported that the Enforcer component of Secure Enterprise is prone to a vulnerability that may allow unauthenticated broadcast traffic to bypass filtering and reach computers in the internal network.
Sygate Enforcer versions prior to 3.5MR1 are reported prone to this issue.
It is reported that the Enforcer component of Secure Enterprise is prone to a vulnerability that may allow unauthenticated broadcast traffic to bypass filtering and reach computers in the internal network.
Sygate Enforcer versions prior to 3.5MR1 are reported prone to this issue.
Exploit / POC
Sygate Secure Enterprise Enforcer Unauthenticated Broadcast Request Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Sygate Secure Enterprise Enforcer Unauthenticated Broadcast Request Bypass Vulnerability
Solution:
It is reported that Sygate Secure Enterprise versions 3.5MR1 and subsequent are not affected by this issue. This information has not been confirmed at the moment.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It is reported that Sygate Secure Enterprise versions 3.5MR1 and subsequent are not affected by this issue. This information has not been confirmed at the moment.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Sygate Secure Enterprise Enforcer Unauthenticated Broadcast Request Bypass Vulnerability
References:
References:
- Sygate Homepage (Sygate)
- Corsaire Security Advisory - Sygate Enforcer unauthenticated broadcast issue ("advisories"
)