CVE Vulnerabilities

CVE-2007-6385

Improper Authentication

Published: Dec 15, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The proxy server in Kerio WinRoute Firewall before 6.4.1 does not properly enforce authentication for HTTPS pages, which has unknown impact and attack vectors. NOTE: it is not clear whether this issue crosses privilege boundaries.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Winroute_firewallKerio*6.4.0 (including)
Winroute_firewallKerio5.0.1 (including)5.0.1 (including)
Winroute_firewallKerio5.0.2 (including)5.0.2 (including)
Winroute_firewallKerio5.0.3 (including)5.0.3 (including)
Winroute_firewallKerio5.0.4 (including)5.0.4 (including)
Winroute_firewallKerio5.0.5 (including)5.0.5 (including)
Winroute_firewallKerio5.0.6 (including)5.0.6 (including)
Winroute_firewallKerio5.0.7 (including)5.0.7 (including)
Winroute_firewallKerio5.0.8 (including)5.0.8 (including)
Winroute_firewallKerio5.0.9 (including)5.0.9 (including)
Winroute_firewallKerio5.1 (including)5.1 (including)
Winroute_firewallKerio5.1.1 (including)5.1.1 (including)
Winroute_firewallKerio5.1.2 (including)5.1.2 (including)
Winroute_firewallKerio5.1.3 (including)5.1.3 (including)
Winroute_firewallKerio5.1.4 (including)5.1.4 (including)
Winroute_firewallKerio5.1.5 (including)5.1.5 (including)
Winroute_firewallKerio5.1.6 (including)5.1.6 (including)
Winroute_firewallKerio5.1.7 (including)5.1.7 (including)
Winroute_firewallKerio5.1.8 (including)5.1.8 (including)
Winroute_firewallKerio5.1.9 (including)5.1.9 (including)
Winroute_firewallKerio5.1.10 (including)5.1.10 (including)
Winroute_firewallKerio5.10 (including)5.10 (including)
Winroute_firewallKerio6.0 (including)6.0 (including)
Winroute_firewallKerio6.0.1 (including)6.0.1 (including)
Winroute_firewallKerio6.0.2 (including)6.0.2 (including)
Winroute_firewallKerio6.0.3 (including)6.0.3 (including)
Winroute_firewallKerio6.0.4 (including)6.0.4 (including)
Winroute_firewallKerio6.0.5 (including)6.0.5 (including)
Winroute_firewallKerio6.0.6 (including)6.0.6 (including)
Winroute_firewallKerio6.0.7 (including)6.0.7 (including)
Winroute_firewallKerio6.0.8 (including)6.0.8 (including)
Winroute_firewallKerio6.0.9 (including)6.0.9 (including)
Winroute_firewallKerio6.0.11 (including)6.0.11 (including)
Winroute_firewallKerio6.1 (including)6.1 (including)
Winroute_firewallKerio6.1.1 (including)6.1.1 (including)
Winroute_firewallKerio6.1.2 (including)6.1.2 (including)
Winroute_firewallKerio6.1.3 (including)6.1.3 (including)
Winroute_firewallKerio6.1.4 (including)6.1.4 (including)
Winroute_firewallKerio6.1.4_patch_1 (including)6.1.4_patch_1 (including)
Winroute_firewallKerio6.1.4_patch_2 (including)6.1.4_patch_2 (including)
Winroute_firewallKerio6.2 (including)6.2 (including)
Winroute_firewallKerio6.2.1 (including)6.2.1 (including)
Winroute_firewallKerio6.2.2 (including)6.2.2 (including)
Winroute_firewallKerio6.2.3 (including)6.2.3 (including)
Winroute_firewallKerio6.3.0 (including)6.3.0 (including)
Winroute_firewallKerio6.3.1 (including)6.3.1 (including)

Potential Mitigations

References