Description
Falcon web server 2.0.0.1020 and earlier allows remote attackers to bypass authentication and read restricted files via an extra / (slash) in the requested URL.
Products
- Blueface Falcon Web Server 2.0.0.1009
 - Blueface Falcon Web Server 2.0.0.1020
 
Questions to Ask Vendors
- Can you confirm whether your systems are affected by CVE-2002-0275, and if so, what steps are you currently taking to mitigate this vulnerability?
 - What is your estimated timeline for fully resolving CVE-2002-0275 in your products or services, and how will you communicate updates on this issue to us as your customer?
 
Recommended Actions
- Check out the advisory links provided below.
 
References