PT-2005-1389 · Ingate · Ingate Firewall
Neil Watson
·
Published
2005-02-10
·
Updated
2017-07-11
·
CVE-2005-0311
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Ingate Firewall versions 4.1.3 and earlier
Description
The issue allows remote authenticated users to retain unauthorized access to resources because the PPTP session for an active user is not terminated when the administrator disables that user from a resource.
Recommendations
For Ingate Firewall versions 4.1.3 and earlier, manually terminate the PPTP session for any user that has been disabled from a resource to prevent unauthorized access.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ingate Firewall