The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which allows attackers to steal digital certificates.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
http://www.bluecoat.com/support/knowledge/advisory_private_key_compromise.html | patch vendor advisory broken link |
http://www.securityfocus.com/bid/10371 | patch vdb entry broken link third party advisory |
http://secunia.com/advisories/11627 | patch vendor advisory broken link third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/16182 | third party advisory vdb entry |
http://www.osvdb.org/6218 | vdb entry broken link |