Vulnerability CVE-2009-2631


Published: 2009-12-04   Modified: 2012-02-13

Description:
Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate; Cisco ASA; SonicWALL E-Class SSL VPN and SonicWALL SSL VPN; SafeNet SecureWire Access Gateway; Juniper Networks Secure Access; Nortel CallPilot; Citrix Access Gateway; and other products, when running in configurations that do not restrict access to the same domain as the VPN, retrieve the content of remote URLs from one domain and rewrite them so they originate from the VPN's domain, which violates the same origin policy and allows remote attackers to conduct cross-site scripting attacks, read cookies that originated from other domains, access the Web VPN session to gain access to internal resources, perform key logging, and conduct other attacks. NOTE: it could be argued that this is a fundamental design problem in any clientless VPN solution, as opposed to a commonly-introduced error that can be fixed in separate implementations. Therefore a single CVE has been assigned for all products that have this design.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Same-origin policy bypass vulnerabilities in several VPN
Juha-Matti Lauri...
08.12.2009

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

Vendor: Aladdin
Product: Safenet securewire access gateway 
Vendor: Sonicwall
Product: E-class ssl vpn 
Product: Ssl vpn 
Vendor: Stonesoft
Product: Stonegate 
Vendor: Cisco
Product: Adaptive security appliance 

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial

 References:
http://kb.juniper.net/KB15799
http://seclists.org/fulldisclosure/2006/Jun/238
http://seclists.org/fulldisclosure/2006/Jun/269
http://seclists.org/fulldisclosure/2006/Jun/270
http://securitytracker.com/id?1023255
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=984744
http://www.kb.cert.org/vuls/id/261869
http://www.securityfocus.com/archive/1/508164/100/0/threaded
http://www.securityfocus.com/bid/37152
http://www.sonicwall.com/us/2123_14882.html
http://www.sonicwall.com/us/2123_14883.html
http://www.stonesoft.com/en/support/security_advisories/2009_03_12.html
http://www.vupen.com/english/advisories/2009/3567
http://www.vupen.com/english/advisories/2009/3568
http://www.vupen.com/english/advisories/2009/3569
http://www.vupen.com/english/advisories/2009/3570
http://www.vupen.com/english/advisories/2009/3571
http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2009/50/025367-01.pdf
https://exchange.xforce.ibmcloud.com/vulnerabilities/54523

Related CVE
CVE-2019-1840
A vulnerability in the DHCPv6 input packet processor of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to restart the server and cause a denial of service (DoS) condition on the affected system. The vulnerability is due...
CVE-2019-1837
A vulnerability in the User Data Services (UDS) API of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the management GUI. The vulnerability is due to i...
CVE-2019-1831
A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper ...
CVE-2019-1830
A vulnerability in Locally Significant Certificate (LSC) management for the Cisco Wireless LAN Controller (WLC) could allow an authenticated, remote attacker to cause the device to unexpectedly restart, which causes a denial of service (DoS) conditio...
CVE-2019-1805
A vulnerability in certain access control mechanisms for the Secure Shell (SSH) server implementation for Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to access a CLI instance on an affected device. T...
CVE-2019-1802
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an a...
CVE-2019-1800
A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist bec...
CVE-2019-1797
A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on the device wi...

Copyright 2019, cxsecurity.com

 

Back to Top