Inconsistent interpretation of HTTP requests in CUJO Smart Firewall - CVE-2018-4030
Published: September 17, 2019
Vulnerability identifier: #VU21163
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-4030
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to conduct an HTTP request smuggling attack on the target system.
The vulnerability exists due to the way the "safe browsing" function parses HTTP requests. A remote attacker can send a specially crafted HTTP request to the application, which incorrectly extracts the "Host" header from captured HTTP, allowing visit any malicious websites and bypass the firewall.
Affected software
CUJO Smart Firewall
How to mitigate CVE-2018-4030
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.