Release date:
Updated on:
Affected Systems:
SEIL/x86 2.35
SEIL/x86 1.00
SEIL/X2 3.75
SEIL/X2 2.30
SEIL/X1 3.75
SEIL/X1 2.30
SEIL/B1 3.75.
SEIL/B1 2.30.
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53821
Cve id: CVE-2012-2632
SEIL Router is a vro from the Japanese SEIL manufacturer.
SEIL/x86 1.00 to 2.35, SEIL/X1 2.30 to 3.75, SEIL/X2 2.30 to 3.75, and SEIL/B1 2.30 to 3.75 have security restrictions on HTTP-Proxy/Gateway bypass. vulnerability, successful exploitation requires setting HTTP-Proxy and disabling 'application-gateway'. Attackers can exploit this vulnerability through specially crafted HTTP requests to bypass the built-in security mechanism.
<* Source: vendor
Link: http://secunia.com/advisories/49365/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SEIL
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.seil.jp/