Release date:
Updated on:
Affected Systems:
Cyberoam DPI
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54291
Cve id: CVE-2012-3372
The Cyberoam UTM device has multiple security features on the same platform, including firewall, VPN, IPS, anti-virus programs, anti-spam, Web filtering, and broadband management.
Cyberoam DPI has a Security Restriction Bypass Vulnerability. After successful exploitation, attackers can perform man-in-the-middle attacks or simulate trusted servers.
<* Source: Runa A. Sandvik
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cyberoam
--------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.cyberoam.com/