Foreman Smart Proxy CVE-2014-3691 SSL Certificate Validation Security Bypass Vulnerability
BID:70320
Info
Foreman Smart Proxy CVE-2014-3691 SSL Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 70320 |
| Class: | Design Error |
| CVE: |
CVE-2014-3691 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2014 12:00AM |
| Updated: | Oct 09 2014 12:00AM |
| Credit: | Murray McAllister |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Foreman Smart Proxy CVE-2014-3691 SSL Certificate Validation Security Bypass Vulnerability
Foreman Smart Proxy is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Foreman Smart Proxy is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Exploit / POC
Foreman Smart Proxy CVE-2014-3691 SSL Certificate Validation Security Bypass Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
Foreman Smart Proxy CVE-2014-3691 SSL Certificate Validation Security Bypass Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Foreman Smart Proxy CVE-2014-3691 SSL Certificate Validation Security Bypass Vulnerability
References:
References: