Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which allows remote malicious users to use the finjan-parameter-type header to (1) restart the service, (2) use the getlastmsg command to view log information, or (3) use the online command to force a policy update from the database server.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
finjan software surfingate 6.0 |
||
finjan software surfingate 6.0_1 |
||
finjan software surfingate 6.0_5 |
||
finjan software surfingate 7.0 |