PT-2019-10763 · Cujo · Cujo Smart Firewall
Published
2019-03-21
·
Updated
2022-06-07
·
CVE-2018-4030
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
CUJO Smart Firewall version 7003
Description
A vulnerability exists in the safe browsing function, specifically in how it parses HTTP requests. The issue lies in the incorrect extraction of the
Host header from captured HTTP requests, allowing an attacker to visit malicious websites and bypass the firewall. An attacker can exploit this by sending a crafted HTTP request.Recommendations
For CUJO Smart Firewall version 7003, consider temporarily disabling the safe browsing function until a patch is available to prevent exploitation. Restrict access to unknown or untrusted websites to minimize the risk of bypassing the firewall. Avoid relying solely on the safe browsing function for security until the issue is resolved.
Exploit
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cujo Smart Firewall