← Zuruck zu CVEs
CVE-2025-34070
CRITICAL9.8
Beschreibung
A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privileged operations. The GFIAgent service, responsible for integration with GFI AppManager, exposes HTTP services on ports 7995 and 7996 without proper authentication. The /proxy handler on port 7996 allows arbitrary forwarding to administrative endpoints when provided with an Appliance UUID, which itself can be retrieved from port 7995. This results in a complete authentication bypass, permitting access to sensitive administrative APIs.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht7/2/2025
Zuletzt geandert9/17/2025
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
gfi:kerio_control
Schwachen (CWE)
CWE-306
Referenzen
https://ssd-disclosure.com/ssd-advisory-kerio-control-authentication-bypass-and-rce/(disclosure@vulncheck.com)
https://vulncheck.com/advisories/gfi-kerio-control-auth-bypass-rce(disclosure@vulncheck.com)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.