PT-2022-11581 · Unknown · Rsfirewall

Daniel Ruf

·

Published

2022-12-15

·

Updated

2025-04-21

·

CVE-2021-4226

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RSFirewall (affected versions not specified)
Description The issue is related to how RSFirewall attempts to identify the original IP address by examining different HTTP headers. A bypass is possible due to the implementation of this functionality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

CVE-2021-4226

Affected Products

Rsfirewall