Skip to: contents, mainnavigation

News archive

Back to archive
Article 25 of 39
11-06-2009

F5 FirePass Cross-Site Scripting vulnerability

Fox-IT discovered a security vulnerability in the 'FirePass' VPN product from F5 Networks. Using this vulnerability, an attacker could manipulate a VPN user's login session to the F5 FirePass VPN interface. After Fox-IT reported the issue confidentially to F5, the company released a HotFix that resolves the problem.

================================================================
Vulnerability discovered: May 01, 2009
Discovered by: Sjoerd Resink, Fox-IT BV
Reported to vendor: May 14, 2009
Fix available: May 28, 2009 ================================================================

PRODUCT
-------------
F5 Networks FirePass SSL VPN controller provides secure access to corporate applications and data using a standard web browser. More information can be found at:
http://www.f5.com/products/firepass/

VULNERABILITY
-------------
Fox-IT discovered a Cross-Site Scripting vulnerability in the F5 Networks FirePass SSL VPN controller. No authentication is required to exploit this vulnerability.

EXPLOITATION
-------------
This vulnerability can be used to execute arbitrary JavaScript code on the computer of a user as if it genuinely originated from the target domain. In order to do this, an attacker would have to lure the user into visiting a specially prepared URL. Pages can be modified in such a way that any data entered into password fields will not only be sent to the F5 FirePass appliance, but also to the attacker. More advanced exploits of XSS also enable attackers to abuse the user’s computer as a stepping stone for launching further attacks on the user's internal network.

FIX
-------------
F5 Networks has released Cumulative HotFix-603-3 for FirePass to address this vulnerability. More information about obtaining and installing this patch can be found at:
https://support.f5.com/kb/en-us/solutions/public/10000/100/sol10143.html

Thanks to F5 Networks for their quick response regarding this issue.

Please click here for more details.

Back to archive
Article 25 of 39