Blue Coat ProxySG Heartbeat Information Disclosure (Heartbleed)

This script is Copyright (C) 2014 Tenable Network Security, Inc.


Synopsis :

The remote device is potentially affected by an information disclosure
vulnerability.

Description :

The remote Blue Coat ProxySG device's SGOS self-reported version is
6.5.3.x prior to 6.5.3.6. It is, therefore, potentially affected by an
information disclosure vulnerability.

An out-of-bounds read error, known as the 'Heartbleed Bug', exists
related to handling TLS heartbeat extensions that could allow an
attacker to obtain sensitive information such as primary key material,
secondary key material, and other protected content.

See also :

http://kb.bluecoat.com/index?page=content&id=SA79
http://www.heartbleed.com

Solution :

Upgrade to version 6.5.3.6 or later.

Risk factor :

High / CVSS Base Score : 9.4
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N)
CVSS Temporal Score : 8.2
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : true

Family: Firewalls

Nessus Plugin ID: 73515 ()

Bugtraq ID: 66690

CVE ID: CVE-2014-0160