PT-2007-4750 · Check Point · Check Point Vpn-1 Edge X Embedded Ngx
Publicado
2007-06-29
·
Atualizado
2018-10-16
·
CVE-2007-3489
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Check Point VPN-1 Edge X Embedded NGX version 7.0.33x
Description
A cross-site request forgery (CSRF) issue exists in the management interface, specifically in pop/WizU.html, allowing remote attackers to perform actions with administrative privileges. This can be achieved by sending a request with the
swuuser and swupass parameters, which can add an administrator account. The management interface lacks a logout capability, making it vulnerable to CSRF attacks without any timing restrictions.Recommendations
For Check Point VPN-1 Edge X Embedded NGX version 7.0.33x, consider disabling access to the pop/WizU.html page in the management interface until a fix is available, and restrict the use of the
swuuser and swupass parameters to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Check Point Vpn-1 Edge X Embedded Ngx