CVE-2004-2107
Last modified
CVE-2004-2107 is a vulnerability of currently unknown severity. Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which allows remote attackers to use the finjan-parameter-type header to (1) restart the service, (2) use the getlastmsg command to view log information, or (3) use the online command to force a policy update from the database server.. EPSS estimates a 7.74% chance of exploitation in the next 30 days.
Description
Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which allows remote attackers to use the finjan-parameter-type header to (1) restart the service, (2) use the getlastmsg command to view log information, or (3) use the online command to force a policy update from the database server.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Finjan Software | Surfingate | 6.0 |
| Finjan Software | Surfingate | 6.0_1 |
| Finjan Software | Surfingate | 6.0_5 |
| Finjan Software | Surfingate | 7.0 |
References
- http://secunia.com/advisories/10714Exploit, Patch
- http://www.securityfocus.com/bid/9478Exploit, Patch
- http://secunia.com/advisories/10714Exploit, Patch
- http://www.securityfocus.com/bid/9478Exploit, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-2107?
How severe is CVE-2004-2107?
How do I fix CVE-2004-2107?
Are you affected by CVE-2004-2107?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
