Description
The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which allows attackers to steal digital certificates.
Product(s):
- Broadcom Blue Coat Security Gateway
- Broadcom BlueCoat Security Gateway 3.0
- Broadcom BlueCoat Security Gateway 3.1.2.2
- Broadcom BlueCoat Security Gateway 3.1.2
- Broadcom BlueCoat Security Gateway 3.1.3.13
- Broadcom BlueCoat Security Gateway 3.1.3.2
- Broadcom BlueCoat Security Gateway 3.1.3.7
- Broadcom BlueCoat Security Gateway 3.1
- Broadcom BlueCoat Security Gateway 3.2.1
Question to Ask Vendors:
- Can you confirm whether your systems are affected by CVE-2004-2397, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-2004-2397 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions:
- Check out the advisory links provided below.