An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and weak access control in the GFIAgent service. The non-transparent proxy on TCP port 3128 can be used to forward unauthenticated requests to internal services such as GFIAgent, bypassing firewall restrictions and exposing internal management endpoints. This enables unauthenticated attackers to access the GFIAgent service on ports 7995 and 7996, retrieve the appliance UUID, and issue administrative requests via the proxy. Exploitation results in full administrative access to the Kerio Control appliance.
An unauthenticated attacker can exploit an unsecured non-transparent proxy listening on TCP port 3128 to redirect requests to internal services, including GFIAgent, thereby bypassing firewall restrictions. Through such constructed requests, it is possible to reach the GFIAgent service on ports 7995 and 7996, retrieve the device UUID identifier, and issue administrative requests through the proxy. This mechanism results from the lack of authentication requirement (CWE-306) for critical management functions, making internal endpoints accessible from outside without any credentials.
The attacker gains full administrative access to the Kerio Control device, which allows taking complete control of the firewall, its configuration, and network traffic in the protected environment. Combined with the RCE capability (indicated in the references), the consequences may include compromise of the entire network infrastructure.
Apply patches available from the manufacturer according to the references. Additionally, as a temporary workaround, consider restricting network access to ports 3128, 7995, and 7996 to trusted hosts only and verify the proxy configuration in the Kerio Control device.
GFI Kerio Control version 9.4.5
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XGfi Kerio Control
APPGfi9.4.5
Related vulnerabilities
GFI Kerio Control – pominięcie uwierzytelnienia w komponencie GFIAgent (Auth Bypass)
RCE w GFI Kerio Control poprzez mechanizm aktualizacji firmware
An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonaut...
A DOM based XSS in GFI Kerio Control v9.3.0 allows embedding of malicious code and manipulating the login page...
GFI Archiver MArc.Core — pominięcie autoryzacji (Authentication Bypass)