Document Title: =============== Astaro Gateway v7.504 - Multiple Web Vulnerabilities References (Source): ==================== http://www.vulnerability-lab.com/get_content.php?id=8 Release Date: ============= 2012-04-07 Vulnerability Laboratory ID (VL-ID): ==================================== 8 Common Vulnerability Scoring System: ==================================== 3.5 Product & Service Introduction: =============================== Das Astaro Security Gateway 625 wurde speziell für den Schutz großer Unternehmen konzipiert. Basierend auf hochwertigen Intel-kompatiblen Serversystemen, einschließlich Dual IntelTM Xeon-Multi-Core-Prozessoren sowie redundanten Highspeed-Festplatten, bietet es selbst für die herausforderndsten Umgebungen optimale Performance und Zuverlässigkeit. Dieser Abschnitt beschreibt detailliert die verfügbaren Sicherheitsanwendungen, technischen Einzelheiten und Einsatzszenarien. (Copy of the Vendor Homepage: https://www.astaro.com/de-de/produkte/hardware-appliance/astaro-security-gateway-625) Abstract Advisory Information: ============================== The vulnerability research team discovers multiple input validation vulnerabilities on Astaros Security Web Gateway v7.504. Vulnerability Disclosure Timeline: ================================== 2011-01-13: Verified by Vulnerability-Lab 2011-06-15: Secure Vendor Notification 2011-11-17: Vendor Reply/Feedback 2012-03-09: Fix/Patch by Vulnerability Lab Check 2012-04-08: Discovery by Vulnerability-Lab Discovery Status: ================= Published Affected Product(s): ==================== Exploitation Technique: ======================= Remote Severity Level: =============== Low Technical Details & Description: ================================ Multiple persistent Input Validation Vulnerabilities are detected on the Astaros Security Gateway application(appliance). The vulnerability allows a local low privileged user account or remote attacker with medium required user inter action to manipulate module contexts on application-side. Result of successful exploitation is session hijacking, phishing & stable context manipulation or client side target exploitation out of the gateway web application context. Vulnerable Module(s): ---- Management -- System Settings (Time&Date | Shell Access) ---- Users -- New User -- New Group -- Authentication / New Server ---- Definitions -- New Interface -- Comment Static Route -- OSPF Interface Settings -- View/Edit Traffic Selector -- New PIM-SM Interface -- New Rendezvous Point Router -- Uplink Monitoring ---- Network -- New Network & Listing -- New Service Definition -- New Time Event Definition Affected: Astaro Security Web Gateway v7.504 Astaro Security Web Gateway v8.x | 2011 Q1-4 - 110, 120, 220, 320, 425, 525 & 625 Pictures: ../1.png ../2.png ../3.png ../4.png ../5.png Proof of Concept (PoC): ======================= The vulnerabilities can be exploited by local attackers with restricted accounts or with medium user inter-action on the remote way. For demonstration or reproduce ... Code Review: Users - User Listing
>"
Known IP addresses of user '>"' Code Review: Add New Network Listing >" (User Network) Code Review: Site to Site VPN - Certificate Listing WebAdmin certificate for >".astaro.com Code Review: Extra RBL Zones - AntiSpam
>"
Solution - Fix & Patch: ======================= Upgrade available since January 2012 (Sophos) Security Risk: ============== The security risk of the persistent input validation vulnerabilities are estimated as medium(+)/(-)high. Credits & Authors: ================== Vulnerability Research Laboratory - Benjamin Kunz Mejri (Rem0ve) & Pim J.F.P. Campers (X4lt) Disclaimer & Information: ========================= The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequential loss of business profits or special damages, even if Vulnerability-Lab or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. We do not approve or encourage anybody to break any vendor licenses, policies, deface websites, hack into databases or trade with fraud/stolen material. Domains: www.vulnerability-lab.com - www.vuln-lab.com - www.vulnerability-lab.com/register Contact: admin@vulnerability-lab.com - support@vulnerability-lab.com - research@vulnerability-lab.com Section: video.vulnerability-lab.com - forum.vulnerability-lab.com - news.vulnerability-lab.com Social: twitter.com/#!/vuln_lab - facebook.com/VulnerabilityLab - youtube.com/user/vulnerability0lab Feeds: vulnerability-lab.com/rss/rss.php - vulnerability-lab.com/rss/rss_upcoming.php - vulnerability-lab.com/rss/rss_news.php Any modified copy or reproduction, including partially usages, of this file requires authorization from Vulnerability Laboratory. Permission to electronically redistribute this alert in its unmodified form is granted. All other rights, including the use of other media, are reserved by Vulnerability-Lab Research Team or its suppliers. All pictures, texts, advisories, sourcecode, videos and other information on this website is trademark of vulnerability-lab team & the specific authors or managers. To record, list (feed), modify, use or edit our material contact (admin@vulnerability-lab.com or support@vulnerability-lab.com) to get a permission. Copyright © 2012 | Vulnerability Laboratory