TROYANOSYVIRUS
Back to CVEs

CVE-2025-34070

CRITICAL
9.8

Description

A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privileged operations. The GFIAgent service, responsible for integration with GFI AppManager, exposes HTTP services on ports 7995 and 7996 without proper authentication. The /proxy handler on port 7996 allows arbitrary forwarding to administrative endpoints when provided with an Appliance UUID, which itself can be retrieved from port 7995. This results in a complete authentication bypass, permitting access to sensitive administrative APIs.

CVE Details

CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published7/2/2025
Last Modified9/17/2025
Sourcenvd
Honeypot Sightings0

Affected Products

gfi:kerio_control

Weaknesses (CWE)

CWE-306

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.