Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

KF Web Server /%00 bug in WebAdmin?

I just installed OpenVAS yesterday for testing and had it do scans against our Sophos UTM.  It came back with the vulnerability "KF Web Server /%00 bug", but when doing a quick Google search I'm not finding anything in regards to the Sophos UTM line.

Is this really anything to worry about?  I've uploaded a screenshot with more details.

 



This thread was automatically locked due to age.
Parents
  • Di you run this against the Internal interface or External?  Do you have Web Filtering enabled and in what mode?  Is Webserver Protection enabled?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • This was ran against the internal interface.  I do have Web Filtering enabled and it's set for Transparent Mode.  Webserver Protection isn't enabled.

  • There's nothing that exploit could possibly do since the UTM uses Apache, not KeyFocus.  In any case, all of the pieces of the UTM are stripped down and hardened to minimize exposure.  You'd have to get in as root at the command line to "see" anything inside of it.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • There's nothing that exploit could possibly do since the UTM uses Apache, not KeyFocus.  In any case, all of the pieces of the UTM are stripped down and hardened to minimize exposure.  You'd have to get in as root at the command line to "see" anything inside of it.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?