[NT] Sygate Enforcer Unauthenticated Broadcast Bypassing
From: SecuriTeam (support_at_securiteam.com)
Date: 08/11/04
- Previous message: SecuriTeam: "[NT] Sygate Enforcer Discovery Packet DoS"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: list@securiteam.com Date: 11 Aug 2004 17:35:04 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Sygate Enforcer Unauthenticated Broadcast Bypassing
------------------------------------------------------------------------
SUMMARY
<http://www.sygate.com/products/universal_enforcement.htm> Sygate
Enforcers are described as "network gateway devices that enforce host
integrity at network access points". Architecturally they function as an
authenticated, packet-filtering firewall device. The Enforcer interacts
with the Sygate Security Agent (SAA [the personal firewall component])
product and limits access to protected networks/hosts to authenticated
clients that comply with a predefined policy.
In practice, the Enforcer does not limit broadcast traffic (both local-net
and all-nets) from passing through prior to authentication, allowing hosts
that are protected by the Enforcer to still be attacked.
DETAILS
Vulnerable Systems:
* Sygate Enforcer version prior to 3.5MR1
CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0593>
CAN-2004-0593
ADDITIONAL INFORMATION
The information has been provided by <mailto:martin.oneal@corsaire.com>
Martin O'Neal.
The original article can be found at:
<http://www.corsaire.com/advisories/c031120-003.txt>
http://www.corsaire.com/advisories/c031120-003.txt
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: SecuriTeam: "[NT] Sygate Enforcer Discovery Packet DoS"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- [NT] Sygate Enforcer Discovery Packet DoS
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... the Enforcer device uses
a number of proprietary protocol ... The Sygate Enforcer product sends a discovery packet
at one-second ... (Securiteam) - [UNIX] Apache mod_auth_pgsql Format String Vulnerability
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Apache mod_auth_pgsql Format
String Vulnerability ... mod_auth_pgsql "allows user authentication (and can log authentication
... The mod_auth_pgsql module for the Apache httpd is a third party ... (Securiteam) - [TOOL] N-View - Network Monitor
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... N-View is a network monitor
for small and medium-sized networks. ... ICMP responses from all hosts, signaling of timeouts
and delays in the GUI ... o graphic display of traffic load for selected network interfaces,
... (Securiteam) - [NT] PGP Authentication and User Managment Bypass
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... PGP Authentication and
User Managment Bypass ... A design flaw allows attackers to bypass authentication with
PGP SDA. ... (Securiteam) - [REVS] Remote Rogue Network Detection
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Remote Rogue Network
Detection ... The techniques listed in this document will not be able to find all rogue
... (Securiteam)