Blue Coat Proxy Security Gateway OS (SGOS) 4.1.2.1 does not enforce CONNECT rules when using Deep Content Inspection, which allows remote attackers to bypass connection filters.
https://exchange.xforce.ibmcloud.com/vulnerabilities/24446
http://www.vupen.com/english/advisories/2006/0401
http://www.secumind.net/content/french/modules/news/article.php?storyid=8
http://www.bluecoat.com/support/knowledge/advisory_connect_denial_ignore.html