what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

F5 FirePass Cross Site Scripting

F5 FirePass Cross Site Scripting
Posted Jun 11, 2009
Authored by Sjoerd Resink

The F5 Networks FirePass SSL VPN controller suffers from a cross site scripting vulnerability.

tags | advisory, xss
SHA-256 | a99fc64227c1de861c79d79fa7b5ad11f7594d5049c4d2c67fa06de529ac3423

F5 FirePass Cross Site Scripting

Change Mirror Download
=======================================
Vulnerability discovered: May 01, 2009
Reported to vendor: May 14, 2009
Fix available: May 28, 2009
=======================================

PRODUCT
-------------
F5 Networks FirePass SSL VPN controller provides secure access to
corporate applications and data using a standard web browser. More
information can be found at:
http://www.f5.com/products/firepass/

VULNERABILITY
-------------
Fox-IT discovered a Cross-Site Scripting vulnerability in the F5
Networks FirePass SSL VPN controller. No authentication is required to
exploit this vulnerability.

EXPLOITATION
-------------
This vulnerability can be used to execute arbitrary JavaScript code on
the computer of a user as if it genuinely originated from the target
domain. In order to do this, an attacker would have to lure the user
into visiting a specially prepared URL. Pages can be modified in such a
way that any data entered into password fields will not only be sent to
the F5 FirePass appliance, but also to the attacker. More advanced
exploits of XSS also enable attackers to abuse the user's computer as a
stepping stone for launching further attacks on the user's internal
network.

FIX
-------------
F5 Networks has released Cumulative HotFix-603-3 for FirePass to address
this vulnerability. More information about obtaining and installing this
patch can be found at:
https://support.f5.com/kb/en-us/solutions/public/10000/100/sol10143.html

Thanks to F5 Networks for their quick response regarding this issue.

Original report at
https://www.fox-it.com/nl/nieuws-en-events/nieuws/laatste-nieuws/nieuwsa
rtikel/f5-firepass-cross-site-scripting-vulnerability/106. Details will
be released in the near future.
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close