ID

VAR-201008-0399


TITLE

Blue Coat ProxySG Privilege Restricted Remote Security Bypass Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2010-1615

DESCRIPTION

Blue Coat ProxySG is a proxy device platform that helps organizations accelerate and protect applications in distributed networks. An administrator limit value with only read permissions allows a small number of commands to be run, the ProxySG configuration cannot be changed, and the commands entered in the management console and CLI are restricted in the ProxySG. An attacker can send commands through an HTTPS URL, bypassing permission restrictions, and allowing administrators with only read permissions to execute all administrator commands. Blue Coat ProxySG is prone to a remote security-bypass vulnerability. A successful attack will result in the complete compromise of an affected appliance. This issue affects the following versions: Blue Coat ProxySG 5.5 Blue Coat ProxySG 5.4 Blue Coat ProxySG 5.3 Blue Coat ProxySG 4.3 Blue Coat ProxySG 4.2

Trust: 0.81

sources: CNVD: CNVD-2010-1615 // BID: 42490

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2010-1615

AFFECTED PRODUCTS

vendor:blue coatmodel:proxysgscope:eqversion:4.2

Trust: 0.6

vendor:blue coatmodel:proxysgscope:eqversion:4.3

Trust: 0.6

vendor:bluemodel:coat systems proxysgscope:eqversion:5.5

Trust: 0.3

vendor:bluemodel:coat systems proxysgscope:eqversion:5.4

Trust: 0.3

vendor:bluemodel:coat systems proxysgscope:eqversion:5.3

Trust: 0.3

vendor:bluemodel:coat systems proxysgscope:eqversion:4.3

Trust: 0.3

vendor:bluemodel:coat systems proxysgscope:eqversion:4.2

Trust: 0.3

vendor:bluemodel:coat systems proxysgscope:neversion:5.5.3.1

Trust: 0.3

sources: CNVD: CNVD-2010-1615 // BID: 42490

THREAT TYPE

network

Trust: 0.3

sources: BID: 42490

TYPE

Design Error

Trust: 0.3

sources: BID: 42490

PATCH

title:Blue Coat ProxySG privilege restricts remote security bypass vulnerability patchesurl:https://www.cnvd.org.cn/patchinfo/show/828

Trust: 0.6

sources: CNVD: CNVD-2010-1615

EXTERNAL IDS

db:BIDid:42490

Trust: 0.9

db:CNVDid:CNVD-2010-1615

Trust: 0.6

sources: CNVD: CNVD-2010-1615 // BID: 42490

REFERENCES

url:https://kb.bluecoat.com/index?page=content&id=sa45http

Trust: 0.6

url:http://www.bluecoat.com/products/sg

Trust: 0.3

url:http://www.bluecoat.com

Trust: 0.3

url:https://kb.bluecoat.com/index?page=content&id=sa45

Trust: 0.3

sources: CNVD: CNVD-2010-1615 // BID: 42490

CREDITS

Thierry Zoller

Trust: 0.3

sources: BID: 42490

SOURCES

db:CNVDid:CNVD-2010-1615
db:BIDid:42490

LAST UPDATE DATE

2022-05-17T01:45:43.336000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2010-1615date:2010-08-18T00:00:00
db:BIDid:42490date:2010-08-16T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2010-1615date:2010-08-18T00:00:00
db:BIDid:42490date:2010-08-16T00:00:00