Overview
Changes to Blue Coat ProxySG local users do not take effect immediately, giving an attacker with known credentials a window of opportunity to use those credentials even if the user was deleted or the password was changed. (CWE-361)
Description
Blue Coat Security Advisory SA77 states: SGOS supports multiple types of authentication realms for authenticating administrative and proxy users. Most authentication realms use remote authentication databases. Locally defined users and user lists are in the local authentication realm. The local authentication realm is typically used for administrative and console access, but can be used for proxy users as well. |
Impact
An attacker with knowledge of existing credentials may be able to log in as that user even after the account was deleted. If the local realm is used for console access then the credentials may be used to compromise administrative access. |
Solution
Apply an Update
If you are unable to upgrade, please consider the following workarounds. |
After changing a password, immediately log in with the new password or attempt to log in with an incorrect password.
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 7.4 | AV:A/AC:M/Au:S/C:C/I:C/A:C |
Temporal | 6.1 | E:F/RL:OF/RC:C |
Environmental | 4.6 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Blue Coat for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
CVE IDs: | CVE-2014-2033 |
Date Public: | 2014-02-21 |
Date First Published: | 2014-02-28 |
Date Last Updated: | 2014-02-28 19:01 UTC |
Document Revision: | 8 |