VPN Bypass Vulnerability in Novell Access Management
CVE-2007-1309

Currently unrated

Key Information:

Vendor
Novell
Vendor
CVE Published:
7 March 2007

Summary

The Novell Access Management 3 SSLVPN Server contains a vulnerability that allows remote authenticated users to bypass VPN restrictions. This can be achieved by manipulating the settings in the policy.txt file. Specifically, attackers can make policy.txt read-only, then disconnect from the VPN and manually modify this critical configuration file. This manipulation can lead to unauthorized access and potential exploitation of network resources.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.