VulnerabilityModified
CVE-2007-6385
The proxy server in Kerio WinRoute Firewall before 6.4.1 does not properly enforce authentication for HTTPS pages, which has unknown impact and attack vectors.
LOW 2.1EPSS 0.37%
Does this matter?
Lower severity and a low EPSS score (0.37%). Track it; it rarely justifies an emergency change on its own.
Description
The proxy server in Kerio WinRoute Firewall before 6.4.1 does not properly enforce authentication for HTTPS pages, which has unknown impact and attack vectors. NOTE: it is not clear whether this issue crosses privilege boundaries.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.37% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- kerio/winroute firewall
- Source
- cve@mitre.org
References
- http://osvdb.org/42122
- http://secunia.com/advisories/28072Vendor Advisory
- http://www.kerio.com/kwf_history.htmlPatch
- http://www.securityfocus.com/bid/26851
- http://www.securitytracker.com/id?1019095
- http://www.vupen.com/english/advisories/2007/4212
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39020
- http://osvdb.org/42122
- http://secunia.com/advisories/28072Vendor Advisory
- http://www.kerio.com/kwf_history.htmlPatch
- http://www.securityfocus.com/bid/26851
- http://www.securitytracker.com/id?1019095
- http://www.vupen.com/english/advisories/2007/4212
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39020
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.