CVE-2021-33600: Denial of Service Vulnerability in Web Interface of F-Secure Internet Gatekeeper
A denial-of-service (DoS) vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. The vulnerability occurs because of an attacker can trigger assertion via malformed HTTP packet to web interface. An unauthenticated attacker could exploit this vulnerability by sending a large username parameter. A successful exploitation could lead to a denial-of-service of the product.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-33600?
CVE-2021-33600 is a denial-of-service (DoS) vulnerability discovered in the web user interface of F-Secure Internet Gatekeeper.
How does CVE-2021-33600 occur?
CVE-2021-33600 occurs because an attacker can trigger an assertion via a malformed HTTP packet to the web interface.
What is the impact of CVE-2021-33600?
The impact of CVE-2021-33600 is that an unauthenticated attacker could exploit this vulnerability to cause a denial-of-service (DoS) condition.
Which versions of F-Secure Internet Gatekeeper are affected by CVE-2021-33600?
CVE-2021-33600 affects F-Secure Internet Gatekeeper versions 5.10 to 5.50.47.
How can I mitigate the vulnerability CVE-2021-33600?
To mitigate CVE-2021-33600, it is recommended to update F-Secure Internet Gatekeeper to a version beyond 5.50.47.