Attachmate Reflection NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
BID:40578
Info
Attachmate Reflection NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 40578 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 04 2010 12:00AM |
| Updated: | Jun 04 2010 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Attachmate Reflection X 14.0.5 Attachmate Reflection X 14.0 Attachmate Reflection X 13.0 Attachmate Reflection X 10 Attachmate Reflection X 0 Attachmate Reflection for UNIX and OpenVMS 14.0.5 Attachmate Reflection for the Multi-Host Enterprise Pro 14.0.5 Attachmate Reflection for IBM 14.0.5 Attachmate Reflection for IBM 14 Attachmate Reflection for HP 14.0.5 Attachmate Reflection 13.0.5 Attachmate Reflection 13.0.4 Attachmate Reflection 14.0 SP1 Attachmate Reflection 14.0 Attachmate Reflection 13.0 |
| Not Vulnerable: |
Attachmate Reflection X 14.1 Attachmate Reflection 14.1 |
Discussion
Attachmate Reflection NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
Attachmate Reflection is prone to a security-bypass vulnerability because the application fails to properly validate the domain name in a signed CA certificate, allowing attackers to substitute malicious SSL certificates for trusted ones.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Versions prior to Reflection 14.1 are vulnerable.
Attachmate Reflection is prone to a security-bypass vulnerability because the application fails to properly validate the domain name in a signed CA certificate, allowing attackers to substitute malicious SSL certificates for trusted ones.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Versions prior to Reflection 14.1 are vulnerable.
Exploit / POC
Attachmate Reflection NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
Attackers use man-in-the-middle attacks to exploit this issue.
Attackers use man-in-the-middle attacks to exploit this issue.
Solution / Fix
Attachmate Reflection NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Attachmate Reflection NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
References:
References:
- Attachmate Homepage (Attachmate)
- Null Prefix Attacks Against SSL/TLS Certificates (Moxie Marlinspike)
- Technical Note 1708 Security Updates and Reflection (Attachmate)