vendor:
Artica Proxy
by:
Dan Duffy
9.8
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: Artica Proxy
Affected Version From: 4.30.00000000
Affected Version To: 4.30.00000000
Patch Exists: YES
Related CWE: CVE-2020-17506
CPE: a:artica:artica_proxy:4.3.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Debian
2020
Artica Proxy 4.3.0 – Authentication Bypass
A vulnerability in Artica Proxy 4.3.0 allows an attacker to bypass authentication by sending a crafted payload to the /fw.login.php?apikey= endpoint. This allows an attacker to gain access to the web interface and execute arbitrary commands.
Mitigation:
Upgrade to the latest version of Artica Proxy.