Search

published date: December 31, 2004

CVE-2004-2397 : The web-based Management Console...

Description

The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which allows attackers to steal digital certificates.

Product(s):

  • Broadcom Blue Coat Security Gateway
  • Broadcom BlueCoat Security Gateway 3.0
  • Broadcom BlueCoat Security Gateway 3.1.2.2
  • Broadcom BlueCoat Security Gateway 3.1.2
  • Broadcom BlueCoat Security Gateway 3.1.3.13
  • Broadcom BlueCoat Security Gateway 3.1.3.2

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2004-2397, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2004-2397 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?