PT-2019-10763 · Cujo · Cujo Smart Firewall

Published

2019-03-21

·

Updated

2022-06-07

·

CVE-2018-4030

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions CUJO Smart Firewall version 7003
Description A vulnerability exists in the safe browsing function, specifically in how it parses HTTP requests. The issue lies in the incorrect extraction of the Host header from captured HTTP requests, allowing an attacker to visit malicious websites and bypass the firewall. An attacker can exploit this by sending a crafted HTTP request.
Recommendations For CUJO Smart Firewall version 7003, consider temporarily disabling the safe browsing function until a patch is available to prevent exploitation. Restrict access to unknown or untrusted websites to minimize the risk of bypassing the firewall. Avoid relying solely on the safe browsing function for security until the issue is resolved.

Exploit

Fix

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-4030

Affected Products

Cujo Smart Firewall