PT-2012-4669 · Cyberoam · Cyberoam Utm

Ben Laurie

+1

·

Publicado

2012-07-09

·

Atualizado

2025-01-27

·

CVE-2012-3372

CVSS v3.1

7.4

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cyberoam UTM appliances (affected versions not specified)
Description The default configuration of Cyberoam UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations. This makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Cyberoam SSL CA certificate in a list of trusted root certification authorities. The vendor disputes the significance of this issue, citing that the appliance does not allow import or export of the private key.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-3372

Produtos afetados

Cyberoam Utm