← Vulnerability feed

Vulnerability record · CVE-2009-2631 · published 4 December 2009

CVE-2009-2631: Aladdin safenet securewire access gateway improper access control vulnerability

Aladdin · Safenet Securewire Access Gateway

Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate; Cisco ASA; SonicWALL E-Class SSL VPN and SonicWALL SSL VPN; SafeNet SecureWire Access Gateway; Juniper Networks Secure Access; Nortel CallPilot; Citrix Access Gateway; and other products, when running in configurations that do not restrict access to the same domain as the VPN, retrieve the content of remote URLs from one domain and rewrite them so they originate from the VPN's domain, which violates the same origin policy and allows remote attackers to conduct cross-site scripting attacks, read cookies that originated from other domains, access the Web VPN session to gain access to internal resources, perform key logging, and conduct other attacks. NOTE: it could be argued that this is a fundamental design problem in any clientless VPN solution, as opposed to a commonly-introduced error that can be fixed in separate implementations. Therefore a single CVE has been assigned for all products that have this design

6.8 CVSS 2.0 Medium EPSS 4.8% · top 8.3% CWE-284 · Improper access controlCWE-264 · Permissions and access controls
6.8CVSS 2.0 base score
4.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
25References
16 Jun 2026Last modified by NVD

Description

Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate; Cisco ASA; SonicWALL E-Class SSL VPN and SonicWALL SSL VPN; SafeNet SecureWire Access Gateway; Juniper Networks Secure Access; Nortel CallPilot; Citrix Access Gateway; and other products, when running in configurations that do not restrict access to the same domain as the VPN, retrieve the content of remote URLs from one domain and rewrite them so they originate from the VPN's domain, which violates the same origin policy and allows remote attackers to conduct cross-site scripting attacks, read cookies that originated from other domains, access the Web VPN session to gain access to internal resources, perform key logging, and conduct other attacks. NOTE: it could be argued that this is a fundamental design problem in any clientless VPN solution, as opposed to a commonly-introduced error that can be fixed in separate implementations. Therefore a single CVE has been assigned for all products that have this design

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-2631 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2007-5603Sonicwall ssl vpn memory buffer overflow vulnerabilityStack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allows remo…EPSS 38%9.3CVE-2007-5814Sonicwall ssl vpn memory buffer overflow vulnerabilityMultiple buffer overflows in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allow remote …EPSS 5.7%8.6CVE-2021-34793Cisco adaptive security appliance vulnerabilityA vulnerability in the TCP Normalizer of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software operating in tr…EPSS 0.58%8.6CVE-2020-3572Cisco adaptive security appliance uncontrolled resource consumption vulnerabilityA vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software …EPSS 1.8%8.6CVE-2020-3436Cisco adaptive security appliance unrestricted file upload vulnerabilityA vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allo…EPSS 1.9%8.6CVE-2020-3304Cisco adaptive security appliance uncontrolled resource consumption vulnerabilityA vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an u…EPSS 3.9%7.8CVE-2013-3382Cisco adaptive security appliance improper input validation vulnerabilityThe Next-Generation Firewall (aka NGFW, formerly CX Context-Aware Security) module 9.x before 9.1.1.9 and 9.1.2.x before 9.1.2.12 for Cisco Adaptive …EPSS 1.9%7.8CVE-2013-1150Cisco adaptive security appliance software improper authentication vulnerabilityThe authentication-proxy implementation on Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(5.31),…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2009-2631), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.