PT-2003-1253 · Watchguard · Watchguard Rssa Appliance+1
Publicado
2003-04-02
·
Atualizado
2008-09-05
·
CVE-2002-1520
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
WatchGuard Firebox Vclass versions 3.2 and earlier
WatchGuard RSSA Appliance version 3.0.2
Description
The issue arises from the CLI interface not properly closing the SSH connection when a -N option is provided during authentication. This allows remote attackers to access the CLI with administrator privileges.
Recommendations
For WatchGuard Firebox Vclass versions 3.2 and earlier, consider disabling the SSH connection option that allows for the -N flag until a patch is available.
For WatchGuard RSSA Appliance version 3.0.2, restrict access to the CLI interface to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Watchguard Firebox Vclass
Watchguard Rssa Appliance