A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privileged operations. The GFIAgent service, responsible for integration with GFI AppManager, exposes HTTP services on ports 7995 and 7996 without proper authentication. The /proxy handler on port 7996 allows arbitrary forwarding to administrative endpoints when provided with an Appliance UUID, which itself can be retrieved from port 7995. This results in a complete authentication bypass, permitting access to sensitive administrative APIs.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Jul 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 02 Jul 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privileged operations. The GFIAgent service, responsible for integration with GFI AppManager, exposes HTTP services on ports 7995 and 7996 without proper authentication. The /proxy handler on port 7996 allows arbitrary forwarding to administrative endpoints when provided with an Appliance UUID, which itself can be retrieved from port 7995. This results in a complete authentication bypass, permitting access to sensitive administrative APIs. | |
Title | GFI Kerio Control GFIAgent Missing Authentication on Administrative Interfaces | |
Weaknesses | CWE-306 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-07-02T13:44:54.945Z
Updated: 2025-07-03T03:55:34.609Z
Reserved: 2025-04-15T19:15:22.550Z
Link: CVE-2025-34070

Updated: 2025-07-02T20:27:28.649Z

Status : Awaiting Analysis
Published: 2025-07-02T14:15:24.527
Modified: 2025-07-03T15:13:53.147
Link: CVE-2025-34070

No data.