PT-2019-10763 · Cujo · Cujo Smart Firewall

Publicado

2019-03-21

·

Atualizado

2022-06-07

·

CVE-2018-4030

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions CUJO Smart Firewall version 7003
Description A vulnerability exists in the safe browsing function, specifically in how it parses HTTP requests. The issue lies in the incorrect extraction of the Host header from captured HTTP requests, allowing an attacker to visit malicious websites and bypass the firewall. An attacker can exploit this by sending a crafted HTTP request.
Recommendations For CUJO Smart Firewall version 7003, consider temporarily disabling the safe browsing function until a patch is available to prevent exploitation. Restrict access to unknown or untrusted websites to minimize the risk of bypassing the firewall. Avoid relying solely on the safe browsing function for security until the issue is resolved.

Exploit

Correção

HTTP Request/Response Smuggling

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-4030

Produtos afetados

Cujo Smart Firewall