Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

ViRobot Linux Server filescan Authentication Bypass

Critical

Synopsis

The remote web server is affected by an authentication bypass flaw.

Description

The remote host is running ViRobot Linux Server, a commercial anti-virus application server. The installed version of ViRobot Linux Server has a flaw such that an attacker can bypass authentication and gain access to its 'filescan' component by supplying a special cookie. An unauthenticated attacker may be able to leverage this flaw to delete arbitrary files on the remote host or disable access to the service by submitting scans of a large number of large files on the remote host.

Solution

Upgrade or patch according to vendor recommendations.