vendor:
FirePass SSL VPN
by:
S. Viehböck
9
CVSS
CRITICAL
Unauthenticated local file inclusion
22
CWE
Product Name: FirePass SSL VPN
Affected Version From: <= 7.0.0 HF-70-6
Affected Version To: 7.0.0 HF-70-7
Patch Exists: YES
Related CWE:
CPE: f5_firepass_ssl_vpn
Platforms Tested:
2012
Unauthenticated local file inclusion
Due to insufficient input validation, an unauthenticated attacker can disclose arbitrary local files with the privileges of the webserver. This includes the user/administrator database. As the attacker-controlled path is passed to the PHP include() function, code execution is also possible. Furthermore, the path is then passed to the unlink() function and therefore can be used to delete arbitrary files in the filesystem.
Mitigation:
Upgrade to version 7.0.0 HF-70-7 or later.