XSS in SSL proxy error page

Advisory ID CVE Number Date discovered Severity Advisory revision
STORM-2015-015 11/17/2015 low v1

Vulnerability details

By using a specially crafted certificate, an attacker can inject javascript code in the error page of SSL proxy.

Impacted products

ProductsSeverityDetail
Stormshield Network Security low SSL Proxy error page suffers from an XSS
Netasq low SSL Proxy error page suffers from an XSS

Revisions

Version Date Description
v1  11/17/2015 Initial release

 



Stormshield Network Security

CVSS v2 Overall Score: 2.5      

Analysis

Impacted version

A specially crafted Common Name containing javascript in a badly signed certificate could result in XSS in the error page of the SSL Proxy.

  • SNS 1.1.0 to 1.4.1
  • SNS 2.0.0 to 2.2.0

Workaround solution

Solution

The ASQ IPS can protect against this attack.

The 1.4.2 update will fix this vulnerability.

The 2.2.1 update will fix this vulnerability.



Access vector Access complexity Authentication Confidentiality impact Integrity impact Availability impact
Network Medium None Partial None None
CVSS Base score: 4.3 CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)
Exploitability Remediation Level Report Confidence
Proof of concept code Official fix Confirmed
CVSS Temporal score: 3.4 CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C)
Collateral Damage Potential Target Distribution
None Medium [26-75%]
CVSS Environmental score: 2.5 CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C/CDP:N/TD:M/CR:ND/IR:ND/AR:ND)


Netasq

CVSS v2 Overall Score: 0      

Analysis

Impacted version

A specially crafted Common Name containing javascript in a badly signed certificate could result in XSS in the error page of the SSL Proxy.

  • Netasq 9.1.0 to 9.1.6

Workaround solution

Solution

The ASQ IPS can protect against this attack.

The 9.1.7 update will fix this vulnerability.



Access vector Access complexity Authentication Confidentiality impact Integrity impact Availability impact
Network Medium None None None None
CVSS Base score: 0 CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:N)
Exploitability Remediation Level Report Confidence
Proof of concept code Official fix Confirmed
CVSS Temporal score: 0 CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:N/E:POC/RL:OF/RC:C)
Collateral Damage Potential Target Distribution
None Medium [26-75%]
CVSS Environmental score: 0 CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:N/E:POC/RL:OF/RC:C/CDP:N/TD:M/CR:ND/IR:ND/AR:ND)