Описание
F-Secure Internet Gatekeeper for Linux 3.x before 3.03 does not require authentication for reading access logs, which allows remote attackers to obtain potentially sensitive information via a TCP session on the admin UI port.
Ссылки
- Patch
- Patch
- Vendor Advisory
- PatchVendor Advisory
- Vendor Advisory
- Patch
- Patch
- Vendor Advisory
- PatchVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:f-secure:internet_gatekeeper:3.02.1221:*:linux:*:*:*:*:*
EPSS
Процентиль: 72%
0.00707
Низкий
5 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
github
больше 3 лет назад
F-Secure Internet Gatekeeper for Linux 3.x before 3.03 does not require authentication for reading access logs, which allows remote attackers to obtain potentially sensitive information via a TCP session on the admin UI port.
EPSS
Процентиль: 72%
0.00707
Низкий
5 Medium
CVSS2
Дефекты
CWE-287