PT-2017-6392 · Viprinet · Viprinet Multichannel Vpn Router 300
Publicado
2017-01-20
·
Atualizado
2018-10-09
·
CVE-2014-9754
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Viprinet MultichannelVPN Router 300 version 2013070830/2013080900
Description
The issue concerns the hardware VPN client's failure to validate the remote VPN endpoint identity through the checking of the endpoint's SSL key before initiating the exchange. This allows an attacker to perform a Man in the Middle attack.
Recommendations
For version 2013070830/2013080900, consider disabling the hardware VPN client until a patch is available that properly validates the remote VPN endpoint identity. Restrict access to the VPN endpoint to minimize the risk of exploitation. Avoid initiating VPN exchanges with unverified endpoints until the issue is resolved.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Viprinet Multichannel Vpn Router 300