Barracuda SSL VPN Multiple Authentication Bypass Vulnerabilities
BID:57540
Info
Barracuda SSL VPN Multiple Authentication Bypass Vulnerabilities
| Bugtraq ID: | 57540 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 24 2013 12:00AM |
| Updated: | Mar 19 2015 08:32AM |
| Credit: | S. Viehböck, SEC Consult Vulnerability Lab |
| Vulnerable: |
Barracuda SSL VPN 2.2.2.203 |
| Not Vulnerable: |
Barracuda SSL VPN 2.0.5 |
Discussion
Barracuda SSL VPN Multiple Authentication Bypass Vulnerabilities
Barracuda SSL VPN is prone to multiple authentication-bypass vulnerabilities.
Remote attackers can exploit these issues to bypass the authentication mechanism and gain unauthorized access. Other attacks may also be possible.
Versions prior to Barracuda SSL VPN 2.0.5 are vulnerable.
Barracuda SSL VPN is prone to multiple authentication-bypass vulnerabilities.
Remote attackers can exploit these issues to bypass the authentication mechanism and gain unauthorized access. Other attacks may also be possible.
Versions prior to Barracuda SSL VPN 2.0.5 are vulnerable.
Exploit / POC
Barracuda SSL VPN Multiple Authentication Bypass Vulnerabilities
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
References
Barracuda SSL VPN Multiple Authentication Bypass Vulnerabilities
References:
References:
- Barracuda SSL VPN Homepage (Barracuda Networks)
- SEC Consult SA-20130124-1 :: Authentication bypass in Barracuda SSL VPN (SEC Consult Vulnerability Lab)