Release date:
Updated on:
Affected Systems:
Syneto uniied Threat Management 1.4.2
Syneto uniied Threat Management 1.3.3 Community Edition
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51707
Syneto Unified Threat Management is a security product with multiple features and protection against internet threats.
Syneto Unified Threat Management has a Cross-Site Request Forgery Vulnerability, which allows remote attackers to execute certain administrator operations and obtain the illegal access permissions of affected applications.
<* Source: Vulnerability Research Laboratory
Link: http://www.vulnerability-lab.com/get_content.php? Id = 373
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Syneto
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.syneto.net/en/network-security/utm