vendor:
Airlock
by:
G. Wagner
N/A
CVSS
N/A
Bypass
20
CWE
Product Name: Airlock
Affected Version From: <= 4.2.4 (without hotfix HF4213)
Affected Version To: 4.2.5
Patch Exists: YES
Related CWE: N/A
CPE: a:ergon:airlock
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
Airlock WAF overlong UTF-8 sequence bypass
The Airlock WAF protection can be completely bypassed by using overlong UTF-8 character representations of the NUL character such as C0 80, E0 80 80 and F0 80 80 80. During the tests no internal knowledge of the WAF was known, but it is suspected that the UTF-8 decoder fails to reject the overlong NUL byte character representations and they get decoded as U+0000 later on. Further the WAF would not perform any checks for attack patterns after the NUL byte.
Mitigation:
Install the hotfix HF4213 provided by the vendor.