Blue Coat ProxySG Deep Content Inspection CONNECT method security bypass

proxysg-connect-bypass-security (24446) The risk level is classified as MediumMedium Risk

Description:

ProxySG from Blue Coat could allow a remote attacker to bypass security. Port number restrictions are not properly enforced on the CONNECT method when content inspection rules are defined in a policy. A remote attacker could exploit this vulnerability to bypass policy restrictions and connect to arbitrary ports.

Platforms Affected:

  • BlueCoat, ProxySG 4.1.2.1

Remedy:

No remedy available as of November 2008.

Consequences:

Bypass Security

References:

  • Blue Coat Proxy Appliances Web site, Web Proxy Server Appliances at http://www.bluecoat.com/products/index.html.
  • CVE-2006-0578: Blue Coat Proxy Security Gateway OS (SGOS) 4.1.2.1 does not enforce CONNECT rules when using Deep Content Inspection, which allows remote attackers to bypass connection filters.
  • OSVDB ID: 22853: Blue Coat ProxySG SGOS HTTP Proxy Arbitrary Port Connection
  • SA18622: Blue Coat ProxySG SGOS Two Security Issues
  • SECTRACK ID: 1015644: Blue Coat ProxySG Policy Error May Let Remote Users Bypass Default CONNECT Policy Rules
  • VUPEN/ADV-2006-0401: Blue Coat ProxySG Security Gateway OS Security Bypass Vulnerabilities

Reported:

Feb 01, 2006

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page