CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-34069

CVSS 9.5v4.0pub. 2025-07-02upd. 2025-09-17

An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and weak access control in the GFIAgent service. The non-transparent proxy on TCP port 3128 can be used to forward unauthenticated requests to internal services such as GFIAgent, bypassing firewall restrictions and exposing internal management endpoints. This enables unauthenticated attackers to access the GFIAgent service on ports 7995 and 7996, retrieve the appliance UUID, and issue administrative requests via the proxy. Exploitation results in full administrative access to the Kerio Control appliance.

🤖 AI Analysis
How it works

An unauthenticated attacker can exploit an unsecured non-transparent proxy listening on TCP port 3128 to redirect requests to internal services, including GFIAgent, thereby bypassing firewall restrictions. Through such constructed requests, it is possible to reach the GFIAgent service on ports 7995 and 7996, retrieve the device UUID identifier, and issue administrative requests through the proxy. This mechanism results from the lack of authentication requirement (CWE-306) for critical management functions, making internal endpoints accessible from outside without any credentials.

Impact

The attacker gains full administrative access to the Kerio Control device, which allows taking complete control of the firewall, its configuration, and network traffic in the protected environment. Combined with the RCE capability (indicated in the references), the consequences may include compromise of the entire network infrastructure.

Mitigation & patch

Apply patches available from the manufacturer according to the references. Additionally, as a temporary workaround, consider restricting network access to ports 3128, 7995, and 7996 to trusted hosts only and verify the proxy configuration in the Kerio Control device.

Who is affected

GFI Kerio Control version 9.4.5

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Gfi Kerio Control

    APP
    Gfi
    9.4.5
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth BypassFirewall
CWE
References

Related vulnerabilities

CVE-2025-34070CRITICAL10.0PL ✓same product

GFI Kerio Control – pominięcie uwierzytelnienia w komponencie GFIAgent (Auth Bypass)

CVE-2025-34071CRITICAL9.4PL ✓same product

RCE w GFI Kerio Control poprzez mechanizm aktualizacji firmware

CVE-2024-52875HIGH8.8same product

An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonaut...

CVE-2019-16414MEDIUM6.1same product

A DOM based XSS in GFI Kerio Control v9.3.0 allows embedding of malicious code and manipulating the login page...

CVE-2026-2038CRITICAL9.8PL ✓same vendor

GFI Archiver MArc.Core — pominięcie autoryzacji (Authentication Bypass)