PT-2017-6392 · Viprinet · Viprinet Multichannel Vpn Router 300

Publicado

2017-01-20

·

Atualizado

2018-10-09

·

CVE-2014-9754

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Viprinet MultichannelVPN Router 300 version 2013070830/2013080900
Description The issue concerns the hardware VPN client's failure to validate the remote VPN endpoint identity through the checking of the endpoint's SSL key before initiating the exchange. This allows an attacker to perform a Man in the Middle attack.
Recommendations For version 2013070830/2013080900, consider disabling the hardware VPN client until a patch is available that properly validates the remote VPN endpoint identity. Restrict access to the VPN endpoint to minimize the risk of exploitation. Avoid initiating VPN exchanges with unverified endpoints until the issue is resolved.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-9754

Produtos afetados

Viprinet Multichannel Vpn Router 300