ID:10992 - Exploit for HTTP response splitting in Kerio Control - CVE-2024-52875

 
Main Vulnerability Database Exploits ID:10992 - Exploit for HTTP response splitting in Kerio Control - CVE-2024-52875

ID:10992 - Exploit for HTTP response splitting in Kerio Control - CVE-2024-52875

Published: December 17, 2024


Vulnerability identifier: #VU101812
Vulnerability risk: Medium
CVE-ID: CVE-2024-52875
CWE-ID: CWE-113
Exploitation vector: Remote access
Vulnerable software:
Kerio Control

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to perform HTTP splitting attacks.

The vulnerability exists due to software does not correclty process CRLF character sequences. A remote attacker can send specially crafted request containing CRLF sequence and make the application to send a split HTTP response.

Successful exploitation of the vulnerability may allow an attacker perform cache poisoning attack.


Remediation

Install updates from vendor's website.