Ingate Firewall 4.1.3 and earlier does not terminate the PPTP session for an active user when the administrator disables that user from a resource, which could allow remote authenticated users to retain unauthorized access to resources.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/19123 | vdb entry |
http://www.securityfocus.com/bid/12383 | vdb entry |
http://marc.info/?l=bugtraq&m=110684375429946&w=2 | mailing list |
http://securitytracker.com/id?1013022 | vdb entry |
http://www.ingate.com/relnote-422.php | |
http://secunia.com/advisories/14060 | third party advisory |