« Volver al listado

CVE-2008-1106

Estado: ModificadaAlta (7.1)—

The management interface in Akamai Client (formerly Red Swoosh) 3322 and earlier allows remote attackers to bypass authentication via an HTTP request that contains (1) no Referer header, or (2) a spoofed Referer header that matches an approved domain, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and force the client to download and execute arbitrary files.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-1106",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.1,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:C/A:N",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "PSIRT-CNA@flexerasoftware.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-06-09T23:32:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/30135",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://secunia.com/secunia_research/2008-19/advisory/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://securityreason.com/securityalert/3930",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/493169/100/0/threaded",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/493170/100/0/threaded",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://www.securitytracker.com/id?1020208",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/1761/references",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42895",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://secunia.com/advisories/30135",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/secunia_research/2008-19/advisory/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/3930",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/493169/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/493170/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1020208",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/1761/references",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42895",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        },
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The management interface in Akamai Client (formerly Red Swoosh) 3322 and earlier allows remote attackers to bypass authentication via an HTTP request that contains (1) no Referer header, or (2) a spoofed Referer header that matches an approved domain, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and force the client to download and execute arbitrary files."
    },
    {
      "lang": "es",
      "value": "La interfaz de administración de Akamai Client (formerly Red Swoosh) 3322 y versiones anteriores permite a atacantes remotos evitar la autenticación a través de una petición HTTP que contiene (1) la cabecera Referer , o (2) una cabecera envenenada Referer que coincide con un dominio válido, lo cual permite a atacantes remotos llevar a cabo un ataque de falsificación de petición en sitios cruzados (CSRF) y forzar al cliente a descargar y ejecutar ficheros de su elección."
    }
  ],
  "lastModified": "2026-06-16T22:51:00.643",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:akamai_technologies:client:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "788B4A79-AD9D-4622-8706-4DA457A58BFC",
              "versionEndIncluding": "3322"
            },
            {
              "criteria": "cpe:2.3:a:red_swoosh:client:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "97803775-8BB2-4BA7-AC5D-A8A9B877237F",
              "versionEndIncluding": "3322"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "PSIRT-CNA@flexerasoftware.com"
}