First published: Sun Aug 26 2012(Updated: )
Blue Coat ProxySG before SGOS 4.3.4.1, 5.x before SGOS 5.4.5.1, 5.5 before SGOS 5.5.4.1, and 6.x before SGOS 6.1.1.1 allows remote authenticated users to execute arbitrary CLI commands by leveraging read-only administrator privileges and establishing an HTTPS session.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Blue Coat ProxySG OS | <=4.3.4 | |
Blue Coat ProxySG OS | =3.2.6 | |
Blue Coat ProxySG OS | =4.1.2.1 | |
Blue Coat ProxySG OS | =4.2.1.2 | |
Blue Coat ProxySG OS | =4.2.1.6 | |
Blue Coat ProxySG OS | =4.2.2 | |
Blue Coat ProxySG OS | =4.2.2.1 | |
Blue Coat ProxySG OS | =4.2.2.2 | |
Blue Coat ProxySG OS | =4.2.3 | |
Blue Coat ProxySG OS | =4.2.3.4 | |
Blue Coat ProxySG OS | =4.2.3.7 | |
Blue Coat ProxySG OS | =4.2.3.12 | |
Blue Coat ProxySG OS | =4.2.3.21 | |
Blue Coat ProxySG OS | =4.2.3.26 | |
Blue Coat ProxySG OS | =4.2.4.1 | |
Blue Coat ProxySG OS | =4.2.5 | |
Blue Coat ProxySG OS | =4.2.5.1 | |
Blue Coat ProxySG OS | =4.2.6 | |
Blue Coat ProxySG OS | =4.2.6.1 | |
Blue Coat ProxySG OS | =4.2.6.4 | |
Blue Coat ProxySG OS | =4.2.7.1 | |
Blue Coat ProxySG OS | =5.2.2.4 | |
Blue Coat ProxySG OS | =5.4.5 | |
Blue Coat ProxySG OS | =5.5.4 | |
Blue Coat ProxySG OS | =6.1 | |
Bluecoat ProxySG | ||
Blue Coat ProxySG SG210-10 | ||
Blue Coat ProxySG SG210-10 | ||
Bluecoat ProxySG | ||
Bluecoat ProxySG | ||
Blue Coat ProxySG SG210-5 | ||
Blue Coat ProxySG SG210-5 | ||
Blue Coat ProxySG SG510-10 | ||
Blue Coat ProxySG SG510-10 | ||
Blue Coat ProxySG SG510-20 | ||
Blue Coat ProxySG SG510-20 | ||
Bluecoat ProxySG | ||
Bluecoat ProxySG | ||
Blue Coat ProxySG SG510-5 | ||
bluecoat ProxySG sg810-10 | ||
bluecoat ProxySG sg810-10 | ||
Blue Coat ProxySG SG810-20 | ||
Blue Coat ProxySG SG810-20 | ||
Blue Coat ProxySG SG810-25 | ||
Blue Coat ProxySG SG810-25 | ||
Blue Coat ProxySG SG810-5 | ||
Blue Coat ProxySG SG9000-10 | ||
Blue Coat ProxySG SG9000-10 | ||
Blue Coat ProxySG SG9000-20 | ||
Blue Coat ProxySG SG9000-20 | ||
Blue Coat ProxySG SG9000-5 | ||
Blue Coat ProxySG SG9000-5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-5189 is rated as a critical vulnerability due to its potential to allow remote authenticated users to execute arbitrary commands.
To mitigate CVE-2010-5189, upgrade to SGOS 4.3.4.1 or later, 5.4.5.1 or later, 5.5.4.1 or later, or 6.1.1.1 or later.
CVE-2010-5189 affects various versions of Blue Coat ProxySG operating systems, specifically those below SGOS 4.3.4.1, 5.4.5.1, and 5.5.4.1.
Attackers can remotely execute arbitrary CLI commands via HTTPS sessions by exploiting read-only administrator privileges.
There are no known workarounds for CVE-2010-5189; upgrading the affected software is the only solution.