ID

VAR-200905-0318


CVE

CVE-2009-1745


TITLE

Armorlogic Profense Web Application Firewall Vulnerabilities that gain access

Trust: 0.8

sources: JVNDB: JVNDB-2009-003434

DESCRIPTION

Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, has a default root password hash, and permits password-based root logins over SSH, which makes it easier for remote attackers to obtain access. Profense Web Application Firewall is prone to a remote security vulnerability

Trust: 1.98

sources: NVD: CVE-2009-1745 // JVNDB: JVNDB-2009-003434 // BID: 79481 // VULHUB: VHN-39191

AFFECTED PRODUCTS

vendor:armorlogicmodel:profense web application firewallscope:eqversion:2.4

Trust: 1.9

vendor:armorlogicmodel:profense web application firewallscope:lteversion:2.2.21

Trust: 1.0

vendor:armorlogicmodel:profense web application firewallscope:eqversion:2.2.21

Trust: 0.9

vendor:armorlogicmodel:profense web application firewallscope:ltversion:2.2.22

Trust: 0.8

sources: BID: 79481 // JVNDB: JVNDB-2009-003434 // CNNVD: CNNVD-200905-265 // NVD: CVE-2009-1745

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2009-1745
value: HIGH

Trust: 1.0

NVD: CVE-2009-1745
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200905-265
value: CRITICAL

Trust: 0.6

VULHUB: VHN-39191
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2009-1745
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-39191
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-39191 // JVNDB: JVNDB-2009-003434 // CNNVD: CNNVD-200905-265 // NVD: CVE-2009-1745

PROBLEMTYPE DATA

problemtype:CWE-255

Trust: 1.9

sources: VULHUB: VHN-39191 // JVNDB: JVNDB-2009-003434 // NVD: CVE-2009-1745

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200905-265

TYPE

trust management

Trust: 0.6

sources: CNNVD: CNNVD-200905-265

CONFIGURATIONS

sources: JVNDB: JVNDB-2009-003434

PATCH

title:Top Pageurl:http://www.armorlogic.com/

Trust: 0.8

sources: JVNDB: JVNDB-2009-003434

EXTERNAL IDS

db:NVDid:CVE-2009-1745

Trust: 2.8

db:XFid:50852

Trust: 0.9

db:JVNDBid:JVNDB-2009-003434

Trust: 0.8

db:BUGTRAQid:20090520 ARMORLOGIC PROFENSE WEB APPLICATION FIREWALL 2.4 MULTIPLE VULNERABILITIES.

Trust: 0.6

db:CNNVDid:CNNVD-200905-265

Trust: 0.6

db:BIDid:79481

Trust: 0.4

db:VULHUBid:VHN-39191

Trust: 0.1

sources: VULHUB: VHN-39191 // BID: 79481 // JVNDB: JVNDB-2009-003434 // CNNVD: CNNVD-200905-265 // NVD: CVE-2009-1745

REFERENCES

url:http://www.securityfocus.com/archive/1/503649/100/0/threaded

Trust: 1.1

url:http://resources.enablesecurity.com/advisories/es-20090500-profense.txt

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/50852

Trust: 1.1

url:http://xforce.iss.net/xforce/xfdb/50852

Trust: 0.9

url:http://www.securityfocus.com/archive/1/archive/1/503649/100/0/threaded

Trust: 0.9

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2009-1745

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2009-1745

Trust: 0.8

sources: VULHUB: VHN-39191 // BID: 79481 // JVNDB: JVNDB-2009-003434 // CNNVD: CNNVD-200905-265 // NVD: CVE-2009-1745

CREDITS

Unknown

Trust: 0.3

sources: BID: 79481

SOURCES

db:VULHUBid:VHN-39191
db:BIDid:79481
db:JVNDBid:JVNDB-2009-003434
db:CNNVDid:CNNVD-200905-265
db:NVDid:CVE-2009-1745

LAST UPDATE DATE

2025-04-10T23:09:20.711000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-39191date:2018-10-10T00:00:00
db:BIDid:79481date:2009-05-21T00:00:00
db:JVNDBid:JVNDB-2009-003434date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200905-265date:2009-06-09T00:00:00
db:NVDid:CVE-2009-1745date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-39191date:2009-05-21T00:00:00
db:BIDid:79481date:2009-05-21T00:00:00
db:JVNDBid:JVNDB-2009-003434date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200905-265date:2009-05-21T00:00:00
db:NVDid:CVE-2009-1745date:2009-05-21T15:30:01.563