A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privileged operations. The GFIAgent service, responsible for integration with GFI AppManager, exposes HTTP services on ports 7995 and 7996 without proper authentication. The /proxy handler on port 7996 allows arbitrary forwarding to administrative endpoints when provided with an Appliance UUID, which itself can be retrieved from port 7995. This results in a complete authentication bypass, permitting access to sensitive administrative APIs.
Metrics
Affected Vendors & Products
References
History
Wed, 17 Sep 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gfi
Gfi kerio Control |
|
| CPEs | cpe:2.3:a:gfi:kerio_control:9.4.5:-:*:*:*:*:*:* | |
| Vendors & Products |
Gfi
Gfi kerio Control |
|
| Metrics |
cvssV3_1
|
Wed, 02 Jul 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Jul 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privileged operations. The GFIAgent service, responsible for integration with GFI AppManager, exposes HTTP services on ports 7995 and 7996 without proper authentication. The /proxy handler on port 7996 allows arbitrary forwarding to administrative endpoints when provided with an Appliance UUID, which itself can be retrieved from port 7995. This results in a complete authentication bypass, permitting access to sensitive administrative APIs. | |
| Title | GFI Kerio Control GFIAgent Missing Authentication on Administrative Interfaces | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-07-02T13:44:54.945Z
Updated: 2025-07-03T03:55:34.609Z
Reserved: 2025-04-15T19:15:22.550Z
Link: CVE-2025-34070
Updated: 2025-07-02T20:27:28.649Z
Status : Analyzed
Published: 2025-07-02T14:15:24.527
Modified: 2025-09-17T13:56:58.470
Link: CVE-2025-34070
No data.