PT-2012-4669 · Cyberoam · Cyberoam Utm

Ben Laurie

+1

·

Published

2012-07-09

·

Updated

2025-01-27

·

CVE-2012-3372

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cyberoam UTM appliances (affected versions not specified)
Description The default configuration of Cyberoam UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations. This makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Cyberoam SSL CA certificate in a list of trusted root certification authorities. The vendor disputes the significance of this issue, citing that the appliance does not allow import or export of the private key.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3372

Affected Products

Cyberoam Utm