Kerio WinRoute Firewall Authentication Credentials Exposure Vulnerability

BID:9071

Info

Kerio WinRoute Firewall Authentication Credentials Exposure Vulnerability

Bugtraq ID: 9071
Class: Design Error
CVE:
Remote: Yes
Local: No
Published: Nov 19 2003 12:00AM
Updated: Nov 19 2003 12:00AM
Credit: The discovery of this vulnerability has been credited to 3APA3A <[email protected]> and Alexander Antipov.
Vulnerable: Kerio WinRoute Firewall 5.1.3
Kerio WinRoute Firewall 5.1.2
Kerio WinRoute Firewall 5.1.1
Kerio WinRoute Firewall 5.1
Kerio WinRoute Firewall 5.0.9
Kerio WinRoute Firewall 5.0.8
Kerio WinRoute Firewall 5.0.7
Kerio WinRoute Firewall 5.0.6
Kerio WinRoute Firewall 5.0.5
Kerio WinRoute Firewall 5.0.4
Kerio WinRoute Firewall 5.0.3
Kerio WinRoute Firewall 5.0.2
- Microsoft Windows 2000 Advanced Server SP3
- Microsoft Windows 2000 Advanced Server SP2
- Microsoft Windows 2000 Advanced Server SP1
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Professional SP3
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Server SP3
- Microsoft Windows 2000 Server SP2
- Microsoft Windows 2000 Server SP1
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Terminal Services SP3
- Microsoft Windows 2000 Terminal Services SP2
- Microsoft Windows 2000 Terminal Services SP1
- Microsoft Windows 2000 Terminal Services
- Microsoft Windows NT Enterprise Server 4.0 SP6a
- Microsoft Windows NT Enterprise Server 4.0 SP6
- Microsoft Windows NT Enterprise Server 4.0 SP5
- Microsoft Windows NT Enterprise Server 4.0 SP4
- Microsoft Windows NT Enterprise Server 4.0 SP3
- Microsoft Windows NT Enterprise Server 4.0 SP2
- Microsoft Windows NT Enterprise Server 4.0 SP1
- Microsoft Windows NT Enterprise Server 4.0
- Microsoft Windows NT Server 4.0 SP6a
- Microsoft Windows NT Server 4.0 SP6
- Microsoft Windows NT Server 4.0 SP5
- Microsoft Windows NT Server 4.0 SP4
- Microsoft Windows NT Server 4.0 SP3
- Microsoft Windows NT Server 4.0 SP2
- Microsoft Windows NT Server 4.0 SP1
- Microsoft Windows NT Server 4.0
- Microsoft Windows NT Terminal Server 4.0 SP6
- Microsoft Windows NT Terminal Server 4.0 SP5
- Microsoft Windows NT Terminal Server 4.0 SP4
- Microsoft Windows NT Terminal Server 4.0 SP3
- Microsoft Windows NT Terminal Server 4.0 SP2
- Microsoft Windows NT Terminal Server 4.0 SP1
- Microsoft Windows NT Terminal Server 4.0
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows XP Home SP1
- Microsoft Windows XP Home
- Microsoft Windows XP Professional SP1
- Microsoft Windows XP Professional
Kerio WinRoute Firewall 5.0.1
- Microsoft Windows 2000 Advanced Server SP3
- Microsoft Windows 2000 Advanced Server SP2
- Microsoft Windows 2000 Advanced Server SP1
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Professional SP3
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Server SP3
- Microsoft Windows 2000 Server SP2
- Microsoft Windows 2000 Server SP1
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Terminal Services SP3
- Microsoft Windows 2000 Terminal Services SP2
- Microsoft Windows 2000 Terminal Services SP1
- Microsoft Windows 2000 Terminal Services
- Microsoft Windows NT Enterprise Server 4.0 SP6a
- Microsoft Windows NT Enterprise Server 4.0 SP6
- Microsoft Windows NT Enterprise Server 4.0 SP5
- Microsoft Windows NT Enterprise Server 4.0 SP4
- Microsoft Windows NT Enterprise Server 4.0 SP3
- Microsoft Windows NT Enterprise Server 4.0 SP2
- Microsoft Windows NT Enterprise Server 4.0 SP1
- Microsoft Windows NT Enterprise Server 4.0
- Microsoft Windows NT Server 4.0 SP6a
- Microsoft Windows NT Server 4.0 SP6
- Microsoft Windows NT Server 4.0 SP5
- Microsoft Windows NT Server 4.0 SP4
- Microsoft Windows NT Server 4.0 SP3
- Microsoft Windows NT Server 4.0 SP2
- Microsoft Windows NT Server 4.0 SP1
- Microsoft Windows NT Server 4.0
- Microsoft Windows NT Terminal Server 4.0 SP6
- Microsoft Windows NT Terminal Server 4.0 SP5
- Microsoft Windows NT Terminal Server 4.0 SP4
- Microsoft Windows NT Terminal Server 4.0 SP3
- Microsoft Windows NT Terminal Server 4.0 SP2
- Microsoft Windows NT Terminal Server 4.0 SP1
- Microsoft Windows NT Terminal Server 4.0
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows XP Home SP1
- Microsoft Windows XP Home
- Microsoft Windows XP Professional SP1
- Microsoft Windows XP Professional
Not Vulnerable: Kerio WinRoute Firewall 5.1.7
Kerio WinRoute Firewall 5.1.6
Kerio WinRoute Firewall 5.1.5
Kerio WinRoute Firewall 5.1.4

Discussion

Kerio WinRoute Firewall Authentication Credentials Exposure Vulnerability

A vulnerability has been discovered in Kerio Winroute Firewall that could lead to remote hosts exposing proxy user's authentication credentials. The problem lies in the fact that Winroute fails to rebuild client browser requests sent through the proxy which contain authentication credentials. Instead, the Proxy-Connection field is modified and the HTTP request is simply forwarded to the appropriate server.

A malicious administrator could exploit this condition by harvesting Winroute authentication credentials contained within requests originating from within a proxied network or system. Access to this information could lead to future attacks.

It should be noted that this is only an issue if authentication is required to make use of the proxy service.

Exploit / POC

Kerio WinRoute Firewall Authentication Credentials Exposure Vulnerability

No exploit is required.

Solution / Fix

Kerio WinRoute Firewall Authentication Credentials Exposure Vulnerability

Solution:
Kerio has addressed this issue in WinRoute Firewall 5.1.4 and more thoroughly in release 5.1.7. Users are advised to upgrade their software as soon as possible.


Kerio WinRoute Firewall 5.0.2

Kerio WinRoute Firewall 5.0.3

Kerio WinRoute Firewall 5.0.4

Kerio WinRoute Firewall 5.0.5

Kerio WinRoute Firewall 5.0.6

Kerio WinRoute Firewall 5.0.7

Kerio WinRoute Firewall 5.0.8

Kerio WinRoute Firewall 5.0.9

Kerio WinRoute Firewall 5.1

Kerio WinRoute Firewall 5.1.1

Kerio WinRoute Firewall 5.1.2

Kerio WinRoute Firewall 5.1.3

References

Kerio WinRoute Firewall Authentication Credentials Exposure Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report