The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which allows attackers to steal digital certificates.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bluecoat_security_gateway | Broadcom | 3.0 (including) | 3.1.3.13 (including) |
Bluecoat_security_gateway | Broadcom | 3.2.1 (including) | 3.2.1 (including) |