SHARE
Facebook X Pinterest WhatsApp

US-CERT warns on SSL-VPN flaws

Dec 3, 2009
security-200x180-redlock_small.jpg

From the

Flaws Without Fixe

s

files:

US-CERT is now warning against a potentially dangerous flaw in the SSL-VPN implementations from over two dozen vendors including industry giant Cisco.

“Clientless SSL VPN products from multiple vendors operate in a way that
breaks fundamental browser security mechanisms,” US-CERT warns. “An attacker could use
these devices to bypass authentication or conduct other web-based
attacks.”

Sounds scary doesn’t it? But I’m not so sure we all need to run for the hills and abandon SSL-VPNs (yet).

At issue is the same origin policy that all modern web browser use. Same origin is basically an attempt to limit the resources that can access data from a particular site. That is, you generally don’t want one site having access to the other sites you have open.

Now the idea of bypassing same origin policy is not new and is at the root of many cross-site request forgery, clickjacking and cross site scripting attacks.

The problem is that with many clientless SSL-VPN implementations, users could potentially be free to visit any site they want. Since they’ve logged into their VPNs and potentially have access to VPN resources such as files shares etc, then all of that could potentially be at risk, if the same origin policy is violated.

Recommended for you...

Facebook Becomes Meta, But Did It Move Too Soon?
Rob Enderle
Oct 29, 2021
Microsoft Gets Rid Of Passwords: I Can Almost Hear Angels Singing
Rob Enderle
Sep 17, 2021
Why AMD Has Been So Successful: Mark Papermaster
Rob Enderle
Sep 9, 2021
Another Crazy Week in Cybersecurity
Paul Shread
Jul 2, 2021
Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.