• Categories
    Category
    {{ postCtrl.tags }}
    • {{ category.tag_type }}

      • {{tag.tag_name}}
      • View more
  • Categories
    Category
    {{ postCtrl.tags }}
    • {{ category.tag_type }}

      • {{tag.tag_name}}
      • View more
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
Tutorial News Comments FAQ Related Articles

VPN apps found insecurely storing session cookies

{{postValue.id}}

Recently, few researchers with National Defense ISAC Remote Access Working Group found out that several VPN applications were insecurely storing authentication information, and also the session cookies in their memory logs and files.

The attackers could easily replay the sessions stored in the VPNs and bypass other authentication methods to access the same apps used by the victims.

Researchers said Palo Alto Networks GlobalProtect product prior to version4.1.0 (CVE-2019-15373) and Pulse Secure Connect Secure product prior to version 8.1R14, 8.2, 8.3R6, and 9.0R2 stored the cookie insecurely in log files.

The firms said to have the vulnerability are Palo Alto Networks GlobalProtect product prior to version 4.1, Pulse Secure Connect Secure product prior to version 8.1R14, 8.2, 8.3R6, and 9.0R2 (CVE-2019-1573), and Cisco AnyConnect product version 4.7.x.

Researchers advised that users affected by vulnerability should update their affected systems immediately to eliminate the vulnerability.

Tags:
mason
Author: 

Comments ( 0 )

No comments available

Add a comment
{{postCtrl.cmtErrMsg}}

Frequently asked questions ( 0 )

No questions available

Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help Isaiah ?
What is the use of SUID & SGID commands

How to set the special permissions to the files and folders using SUID and SGID commands...

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.