Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which allows remote attackers to use the finjan-parameter-type header to (1) restart the service, (2) use the getlastmsg command to view log information, or (3) use the online command to force a policy update from the database server.
| Software | From | Fixed in |
|---|---|---|
| finjan_software / surfingate | 6.0_5 | 6.0_5.x |
| finjan_software / surfingate | 6.0 | 6.0.x |
| finjan_software / surfingate | 7.0 | 7.0.x |
| finjan_software / surfingate | 6.0_1 | 6.0_1.x |