ManageEngine Firewall Analyzer 12.5.x < 12.5.657 / 12.6.x < 12.6.002 / 12.6.104 / 12.6.118 Authenticate Bypass

high Nessus Plugin ID 164450

Synopsis

The remote web server hosts an application that is affected by an authentication bypass vulnerability.

Description

The version of ManageEngine Firewall Analyzer running on the remote web server 12.5.x prior to 12.5.657, or 12.6.x prior to 12.6.002 / 12.6.104 / 12.6.118. It is, there, affected by an authentication bypass vulnerability. Due to the lack of proper request handling an unauthenticated, remote attacker can retrieve the API key of a valid user and access external APIs.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade ManageEngine Firewall Analyzer according to the vendor advisory.

See Also

http://www.nessus.org/u?fb5ffc1c

Plugin Details

Severity: High

ID: 164450

File Name: manageengine_firewall_analyzer_cve-2022-36923.nasl

Version: 1.3

Type: remote

Family: CGI abuses

Published: 8/26/2022

Updated: 12/6/2022

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Temporal Vector: E:U/RL:OF/RC:C

CVSS Score Source: CVE-2022-36923

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:zohocorp:manageengine_firewall_analyzer

Required KB Items: installed_sw/ManageEngine Firewall Analyzer

Exploit Ease: No known exploits are available

Patch Publication Date: 7/27/2022

Vulnerability Publication Date: 7/27/2022

Reference Information

CVE: CVE-2022-36923

IAVA: 2022-A-0340