CVE-2004-2397: High severity bluecoat Security Gateway Os vulnerability
The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which allows attackers to steal digital certificates.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2397?
CVE-2004-2397 is categorized as a high severity vulnerability due to its potential to expose sensitive private keys.
How do I fix CVE-2004-2397?
To fix CVE-2004-2397, update to a version of Blue Coat Security Gateway OS that does not store private keys and passphrases in plaintext.
What versions are affected by CVE-2004-2397?
CVE-2004-2397 affects Blue Coat Security Gateway OS versions 3.0, 3.1, and 3.2.1.
What impact does CVE-2004-2397 have on my system?
The impact of CVE-2004-2397 includes the risk of unauthorized access to digital certificates due to plaintext logging of private keys.
Is CVE-2004-2397 a common vulnerability?
CVE-2004-2397 is relatively common among security environments using affected versions of Blue Coat Security Gateway, making its mitigation critical.