First published: Wed Feb 12 2020(Updated: )
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Barracuda Web Application Firewall | =7.8.1.013 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-2595 is critical with a CVSS score of 9.8.
Remote attackers can bypass authentication by leveraging a permanent authentication token obtained from a query string.
Barracuda Web Application Firewall (WAF) 7.8.1.013 is affected by CVE-2014-2595.
Yes, upgrading to a version of Barracuda Web Application Firewall (WAF) that is not affected by the vulnerability can fix CVE-2014-2595.
You can find more information about CVE-2014-2595 at the following references: [http://packetstormsecurity.com/files/127740/Barracuda-WAF-Authentication-Bypass.html](http://packetstormsecurity.com/files/127740/Barracuda-WAF-Authentication-Bypass.html), [http://seclists.org/fulldisclosure/2014/Aug/5](http://seclists.org/fulldisclosure/2014/Aug/5), [http://www.osvdb.org/109782](http://www.osvdb.org/109782).