MacMusic  |  PcMusic  |  440 Software  |  440 Forums  |  440TV  |  Zicos
vpn
Recherche

Some Enterprise VPN Apps Store Authentication/Session Cookies Insecurely

vendredi 12 avril 2019, 20:03 , par Slashdot
At least four Virtual Private Network (VPN) applications sold or made available to enterprise customers share security flaws, warns the Carnegie Mellon University CERT Coordination Center (CERT/CC) and the Department of Homeland Security's Computer Emergency Response Center (US-CERT). From a report: VPN apps from Cisco, F5 Networks, Palo Alto Networks, and Pulse Secure are impacted, CERT/CC analyst Madison Oliver said in a security alert published earlier today, echoed by the DHS' US-CERT. All four have been confirmed to store authentication and/or session cookies in an non-encrypted form inside a computer's memory or log files saved on disk.

Read more of this story at Slashdot.
rss.slashdot.org/~r/Slashdot/slashdot/~3/Vmx6Sr8PG3Y/some-enterprise-vpn-apps-store-authenticationse...
News copyright owned by their original publishers | Copyright © 2004 - 2024 Zicos / 440Network
Date Actuelle
sam. 20 avril - 00:37 CEST