Vulnerabilities > CVE-2004-0612 - Security Bypass vulnerability in Zonelabs Zonealarm 5.0.590.015

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
zonelabs

Summary

The Mobile Code filter in ZoneAlarm Pro 5.0.590.015 does not filter mobile code within an SSL encrypted session, which could allow remote attackers to bypass the mobile code filtering. NOTE: it has been disputed by the vendor that this behavior is required by the SSL specification.

Vulnerable Configurations

Part Description Count
Application
Zonelabs
1