Support

Rufen Sie uns an!

+49 6201 71009 -0

Gerne helfen wir Ihnen weiter!

+49 6201 71009 -0

Mo. – Fr.: 08:00 Uhr – 17:00 Uhr

Follow

Blog

Home  /  Allgemein   /  WatchGuard   /  CERT VPN Application Vulnerabilities: Is WatchGuard Affected?

CERT VPN Application Vulnerabilities: Is WatchGuard Affected?

Vulnerability Overview

On April 14th, Carnegie Mellon University’s CERT Coordination Center released vulnerability advisory VU#192371, which disclosed security vulnerabilities in several mobile VPN clients from multiple vendors.

In general, the disclosed vulnerabilities involved insecure storage of authentication and session information. Researchers found that some VPN clients stored session cookies unencrypted in log files and in memory. An attacker with access to a system with an active VPN session could potentially scrape valid session information out of memory or log files and replay the session to open a valid VPN connection.

CERT VPN Application Vulnerabilities: Is WatchGuard Affected?