CVE-2007-6385: Low severity Kerio Winroute Firewall vulnerability
The proxy server in Kerio WinRoute Firewall before 6.4.1 does not properly enforce authentication for HTTPS pages, which has unknown impact and attack vectors. NOTE: it is not clear whether this issue crosses privilege boundaries.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6385?
CVE-2007-6385 is classified as having an unknown severity level due to the lack of explicit information regarding its impact and attack vectors.
How do I fix CVE-2007-6385?
To remediate CVE-2007-6385, it is recommended to upgrade to Kerio WinRoute Firewall version 6.4.1 or higher.
What versions of Kerio WinRoute Firewall are affected by CVE-2007-6385?
CVE-2007-6385 affects multiple versions of Kerio WinRoute Firewall, including all versions prior to 6.4.1.
Is authentication enforced for HTTPS pages in Kerio WinRoute Firewall due to CVE-2007-6385?
No, CVE-2007-6385 indicates that the proxy server in the affected versions of Kerio WinRoute Firewall does not properly enforce authentication for HTTPS pages.
What is the impact of CVE-2007-6385?
The impact of CVE-2007-6385 is uncertain, as it has not been explicitly defined, making it difficult to ascertain the potential risks.