CVE-2020-37095: Cyberoam Authentication Client 2.1.2.7 - Buffer Overflow (SEH)
Cyberoam Authentication Client 2.1.2.7 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) memory. Attackers can craft a malicious input in the 'Cyberoam Server Address' field to trigger a bind TCP shell on port 1337 with system-level access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37095?
CVE-2020-37095 has a high severity rating due to its potential for remote code execution via a buffer overflow.
How do I fix CVE-2020-37095?
To fix CVE-2020-37095, update the Cyberoam Authentication Client to the latest version that addresses this vulnerability.
What systems are affected by CVE-2020-37095?
CVE-2020-37095 specifically affects Cyberoam Authentication Client version 2.1.2.7.
What kind of attack does CVE-2020-37095 enable?
CVE-2020-37095 enables remote attackers to execute arbitrary code on the affected system.
What should I do if I cannot upgrade to fix CVE-2020-37095?
If you cannot upgrade, temporarily disable the Cyberoam Authentication Client until a patch is available.