First published: Mon Feb 02 2015(Updated: )
Blue Coat ProxyClient before 3.3.3.3 and 3.4.x before 3.4.4.10 and Unified Agent before 4.1.3.151952 does not properly validate certain certificates, which allows man-in-the-middle attackers to spoof ProxySG Client Managers, and consequently modify configurations and execute arbitrary software updates, via a crafted certificate.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bluecoat ProxyClient | >=3.3<3.3.3.3 | |
Bluecoat ProxyClient | >=3.4<3.4.4.10 | |
Bluecoat Unified Agent | <=4.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1454 has a high severity rating due to its potential for man-in-the-middle attacks.
To mitigate CVE-2015-1454, upgrade Blue Coat ProxyClient to version 3.3.3.3 or later and Unified Agent to version 4.1.3.151952 or later.
CVE-2015-1454 allows attackers to spoof ProxySG Client Managers, potentially leading to unauthorized configuration changes.
All versions of Blue Coat ProxyClient before 3.3.3.3 and 3.4.x before 3.4.4.10 and Unified Agent versions before 4.1.3 are affected by CVE-2015-1454.
Organizations using vulnerable versions of Blue Coat ProxyClient and Unified Agent are at risk from CVE-2015-1454.