Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid session and replaying them against the remote administration server.
| Software | From | Fixed in |
|---|---|---|
| kerio / personal_firewall_2 | 2.1.2 | 2.1.2.x |
| kerio / personal_firewall_2 | 2.1.4 | 2.1.4.x |
| kerio / personal_firewall_2 | 2.1.1 | 2.1.1.x |
| kerio / personal_firewall_2 | 2.1 | 2.1.x |
| kerio / personal_firewall_2 | 2.1.3 | 2.1.3.x |