SyGate Non-Authenticated Remote Administration Vulnerability

BID:952

Info

SyGate Non-Authenticated Remote Administration Vulnerability

Bugtraq ID: 952
Class: Configuration Error
CVE:
Remote: Yes
Local: Yes
Published: Jan 27 2000 12:00AM
Updated: Jan 27 2000 12:00AM
Credit: Discovered and posted to Bugtraq on Jan 27, 2000 by Robert Hillery <[email protected]>.
Vulnerable: Sybergen SyGate 3.11
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
Sybergen SyGate 2.0
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
Not Vulnerable:

Discussion

SyGate Non-Authenticated Remote Administration Vulnerability

SyGate includes a non-documented feature called the Remote Administration Engine (RAE). This feature opens port 7323, and provides a user interface to any incoming telnet session. This interface requires no authentication of any kind, and includes the ability to stop the SyGate service, display various statistics on the SyGate process, and display all TCP or UDP connections, allowing an attacker to generate a map of the internal network.

Exploit / POC

SyGate Non-Authenticated Remote Administration Vulnerability

telnet target:7323

Solution / Fix

SyGate Non-Authenticated Remote Administration Vulnerability

Solution:
Sybergen has released new builds which correct this issue, available at:

SyGate 3.11 Build 563
http://www.sygate.com/SG563.exe

Upgrading SyGate may require that you upgrade the following two products if you are also running them:

Sybergen Access Server Build 558
http://www.sygate.com/SA558.exe

Sybergen Secure Desktop Build 182
http://www.sygate.com/SD182.exe

References

SyGate Non-Authenticated Remote Administration Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report