CVE-2005-0311: Medium severity ingate ingate firewall vulnerability
Ingate Firewall 4.1.3 and earlier does not terminate the PPTP session for an active user when the administrator disables that user from a resource, which could allow remote authenticated users to retain unauthorized access to resources.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0311?
CVE-2005-0311 is considered a medium severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2005-0311?
To fix CVE-2005-0311, upgrade to Ingate Firewall version 4.1.4 or later.
What consequences can arise from CVE-2005-0311?
CVE-2005-0311 can allow remote authenticated users to retain unauthorized access to protected resources after their accounts have been disabled.
Which versions of Ingate Firewall are affected by CVE-2005-0311?
CVE-2005-0311 affects Ingate Firewall versions 3.2, 3.2.1, 3.3.1, and 4.1.3 and earlier.
What type of attack does CVE-2005-0311 enable?
CVE-2005-0311 enables an attacker to exploit user session persistence and maintain access rights even after being disabled.