ID

VAR-201505-0075


CVE

CVE-2015-0962


TITLE

Barracuda Web Filter insecurely performs SSL inspection

Trust: 0.8

sources: CERT/CC: VU#534407

DESCRIPTION

Barracuda Web Filter 7.x and 8.x before 8.1.0.005, when SSL Inspection is enabled, uses the same root Certification Authority certificate across different customers' installations, which makes it easier for remote attackers to conduct man-in-the-middle attacks against SSL sessions by leveraging the certificate's trust relationship. Supplementary information : CWE Vulnerability type by CWE-18: Source Code ( Source code ) Has been identified. http://cwe.mitre.org/data/definitions/18.htmlBy using the trust relationship of the certificate by a third party, SSL Man-in-the-middle attacks on sessions (man-in-the-middle attack) May be executed. Barracuda Web Filter is prone to multiple security-bypass vulnerabilities. Successfully exploiting these issues allow attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks. The gateway supports content filtering, advanced policies, and network threat protection. There is a security vulnerability in Barracuda Networks Web Filter 7.x version and 8.x version before 8.1.0.005

Trust: 2.79

sources: NVD: CVE-2015-0962 // CERT/CC: VU#534407 // JVNDB: JVNDB-2015-002800 // BID: 74384 // VULHUB: VHN-78908 // VULMON: CVE-2015-0962

AFFECTED PRODUCTS

vendor:barracudamodel:web filterscope:eqversion:7.0

Trust: 1.9

vendor:barracudamodel:web filterscope:eqversion:7.1.0

Trust: 1.6

vendor:barracudamodel:web filterscope:eqversion:8.0.002

Trust: 1.6

vendor:barracudamodel:web filterscope:eqversion:7.0.1

Trust: 1.6

vendor:barracudamodel:web filterscope:eqversion:8.0.003

Trust: 1.6

vendor:barracudamodel:web filterscope:eqversion:8.0

Trust: 1.6

vendor:barracudamodel: - scope: - version: -

Trust: 0.8

vendor:barracudamodel:web filter osscope:eqversion:7.x

Trust: 0.8

vendor:barracudamodel:web filter osscope:ltversion:of 8.x

Trust: 0.8

vendor:barracudamodel:web filter osscope:eqversion:8.1.0.005

Trust: 0.8

vendor:barracudamodel:web filterscope:eqversion:8.1.3

Trust: 0.3

vendor:barracudamodel:web filterscope:eqversion:7.1

Trust: 0.3

vendor:barracudamodel:web filterscope:neversion:8.1.0.005

Trust: 0.3

sources: CERT/CC: VU#534407 // BID: 74384 // JVNDB: JVNDB-2015-002800 // CNNVD: CNNVD-201505-022 // NVD: CVE-2015-0962

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-0962
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-0962
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201505-022
value: MEDIUM

Trust: 0.6

VULHUB: VHN-78908
value: MEDIUM

Trust: 0.1

VULMON: CVE-2015-0962
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-0962
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-78908
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-78908 // VULMON: CVE-2015-0962 // JVNDB: JVNDB-2015-002800 // CNNVD: CNNVD-201505-022 // NVD: CVE-2015-0962

PROBLEMTYPE DATA

problemtype:CWE-18

Trust: 1.1

problemtype:CWE-Other

Trust: 0.8

sources: VULHUB: VHN-78908 // JVNDB: JVNDB-2015-002800 // NVD: CVE-2015-0962

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201505-022

TYPE

Design Error

Trust: 0.3

sources: BID: 74384

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-002800

PATCH

title:Barracuda delivers updated SSL Inspection featureurl:https://blog.barracuda.com/2015/04/28/barracuda-delivers-updated-ssl-inspection-feature/

Trust: 0.8

title:Barracuda Web Filter Update for SSL Inspection Certificate Handlingurl:https://techlib.barracuda.com/BWF/UpdateSSLCerts

Trust: 0.8

title:Barracuda Web Filter, SSL Inspection, CVE-2015-0961 and CVE-2015-0962url:https://www.barracuda.com/support/techalerts

Trust: 0.8

sources: JVNDB: JVNDB-2015-002800

EXTERNAL IDS

db:CERT/CCid:VU#534407

Trust: 3.7

db:NVDid:CVE-2015-0962

Trust: 2.9

db:JVNid:JVNVU99597998

Trust: 0.8

db:JVNDBid:JVNDB-2015-002800

Trust: 0.8

db:CNNVDid:CNNVD-201505-022

Trust: 0.7

db:SECUNIAid:64292

Trust: 0.6

db:BIDid:74384

Trust: 0.4

db:VULHUBid:VHN-78908

Trust: 0.1

db:VULMONid:CVE-2015-0962

Trust: 0.1

sources: CERT/CC: VU#534407 // VULHUB: VHN-78908 // VULMON: CVE-2015-0962 // BID: 74384 // JVNDB: JVNDB-2015-002800 // CNNVD: CNNVD-201505-022 // NVD: CVE-2015-0962

REFERENCES

url:http://www.kb.cert.org/vuls/id/534407

Trust: 2.9

url:https://techlib.barracuda.com/bwf/updatesslcerts

Trust: 2.6

url:https://www.barracuda.com/support/techalerts

Trust: 2.1

url:https://blog.barracuda.com/2015/04/28/barracuda-delivers-updated-ssl-inspection-feature/

Trust: 1.8

url:https://www.cert.org/blogs/certcc/post.cfm?entryid=221

Trust: 1.6

url:http://cuda.co/15076

Trust: 0.8

url:https://certcheck.barracudalabs.com

Trust: 0.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-0962

Trust: 0.8

url:http://jvn.jp/vu/jvnvu99597998/index.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-0962

Trust: 0.8

url:http://secunia.com/advisories/64292

Trust: 0.6

url:https://www.barracuda.com/products/category/index

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/18.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://www.securityfocus.com/bid/74384

Trust: 0.1

url:https://www.rapid7.com/db/vulnerabilities/windows-hotfix-ms16-036

Trust: 0.1

sources: CERT/CC: VU#534407 // VULHUB: VHN-78908 // VULMON: CVE-2015-0962 // BID: 74384 // JVNDB: JVNDB-2015-002800 // CNNVD: CNNVD-201505-022 // NVD: CVE-2015-0962

CREDITS

Barracuda Networks

Trust: 0.3

sources: BID: 74384

SOURCES

db:CERT/CCid:VU#534407
db:VULHUBid:VHN-78908
db:VULMONid:CVE-2015-0962
db:BIDid:74384
db:JVNDBid:JVNDB-2015-002800
db:CNNVDid:CNNVD-201505-022
db:NVDid:CVE-2015-0962

LAST UPDATE DATE

2025-04-13T23:32:45.826000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#534407date:2015-04-28T00:00:00
db:VULHUBid:VHN-78908date:2015-05-27T00:00:00
db:VULMONid:CVE-2015-0962date:2015-05-27T00:00:00
db:BIDid:74384date:2015-04-28T00:00:00
db:JVNDBid:JVNDB-2015-002800date:2015-05-28T00:00:00
db:CNNVDid:CNNVD-201505-022date:2015-05-26T00:00:00
db:NVDid:CVE-2015-0962date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CERT/CCid:VU#534407date:2015-04-28T00:00:00
db:VULHUBid:VHN-78908date:2015-05-25T00:00:00
db:VULMONid:CVE-2015-0962date:2015-05-25T00:00:00
db:BIDid:74384date:2015-04-28T00:00:00
db:JVNDBid:JVNDB-2015-002800date:2015-05-28T00:00:00
db:CNNVDid:CNNVD-201505-022date:2015-05-04T00:00:00
db:NVDid:CVE-2015-0962date:2015-05-25T22:59:04.037