Vulnerabilities > CVE-2014-2595 - Insufficient Session Expiration vulnerability in Barracuda web Application Firewall 7.8.1.013

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
barracuda
CWE-613
critical
exploit available

Summary

Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.

Vulnerable Configurations

Part Description Count
Application
Barracuda
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionBarracuda Web Application Firewall Authentication Bypass Vulnerability. CVE-2014-2595. Remote exploit for hardware platform
idEDB-ID:39278
last seen2016-02-04
modified2014-08-04
published2014-08-04
reporterNick Hayes
sourcehttps://www.exploit-db.com/download/39278/
titleBarracuda Web Application Firewall Authentication Bypass Vulnerability

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/127740/barracuda-bypass.txt
idPACKETSTORM:127740
last seen2016-12-05
published2014-08-04
reporterNick Hayes
sourcehttps://packetstormsecurity.com/files/127740/Barracuda-WAF-Authentication-Bypass.html
titleBarracuda WAF Authentication Bypass