PT-2012-4669 · Cyberoam · Cyberoam Utm
Ben Laurie
+1
·
Publicado
2012-07-09
·
Atualizado
2025-01-27
·
CVE-2012-3372
CVSS v3.1
7.4
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cyberoam UTM appliances (affected versions not specified)
Description
The default configuration of Cyberoam UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations. This makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the
Cyberoam SSL CA certificate in a list of trusted root certification authorities. The vendor disputes the significance of this issue, citing that the appliance does not allow import or export of the private key.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cyberoam Utm