Kerlink KerOS Firewall Bypass Vulnerability Allowing Unauthorized UDP Access
Vulnerability
A partial firewall bypass vulnerability has been identified in Kerlink devices running KerOS versions 5.0 through 5.11. Due to a misconfiguration in the iptables firewall, these devices incorrectly accept specially crafted UDP packets. This flaw enables attackers to bypass the firewall and access UDP-based services that would normally be protected.
Impact
Exploitation of this vulnerability allows for a partial bypass of the firewall, enabling unauthorized access to UDP services that should be shielded from such traffic.
Remediation
Users are advised to upgrade to KerOS version 5.12, which addresses this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
