Kerio Personal Firewall Replay Attack Vulnerability
BID:7179
Info
Kerio Personal Firewall Replay Attack Vulnerability
| Bugtraq ID: | 7179 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 28 2003 12:00AM |
| Updated: | Apr 28 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Emiliano Kargieman, Hernán Gips and Javier Burroni from Core Security Technologies. |
| Vulnerable: |
Kerio Personal Firewall 2 2.1.4 Kerio Personal Firewall 2 2.1.3 Kerio Personal Firewall 2 2.1.2 Kerio Personal Firewall 2 2.1.1 Kerio Personal Firewall 2 2.1 |
| Not Vulnerable: | |
Discussion
Kerio Personal Firewall Replay Attack Vulnerability
Kerio Personal Firewall has been reported prone to a replay attack vulnerability.
It has been reported that Kerio Personal Firewall is vulnerable to a replay attack against the authenticated/encrypted channel for remote administration. A remote attacker, who has the ability to capture network traffic destined for the Kerio Personal Firewall, may replay communication data captured from a valid remote Firewall administration session.
An attacker may exploit this vulnerability to capture configuration changes or disable firewall directives and replay the commands at the attackers convenience.
Kerio Personal Firewall has been reported prone to a replay attack vulnerability.
It has been reported that Kerio Personal Firewall is vulnerable to a replay attack against the authenticated/encrypted channel for remote administration. A remote attacker, who has the ability to capture network traffic destined for the Kerio Personal Firewall, may replay communication data captured from a valid remote Firewall administration session.
An attacker may exploit this vulnerability to capture configuration changes or disable firewall directives and replay the commands at the attackers convenience.
Exploit / POC
Kerio Personal Firewall Replay Attack Vulnerability
There is no exploit required.
There is no exploit required.