CVE Vulnerabilities

CVE-2004-2107

Published: Dec 31, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which allows remote attackers to use the finjan-parameter-type header to (1) restart the service, (2) use the getlastmsg command to view log information, or (3) use the online command to force a policy update from the database server.

Affected Software

NameVendorStart VersionEnd Version
SurfingateFinjan_software6.0 (including)6.0 (including)
SurfingateFinjan_software6.0_1 (including)6.0_1 (including)
SurfingateFinjan_software6.0_5 (including)6.0_5 (including)
SurfingateFinjan_software7.0 (including)7.0 (including)

References