Multiple Kerio products contain a flaw that may allow a remote denial of service. The issue is triggered during the pre-authentication state. If a remote attacker forces the system to "compute unexpected conditions", "perform cryptographic operations" or exceed the limit of maximum number of user connections, it will result in loss of availability for the service.
Classification
Location:
Remote/Network Access Required
Attack Type:
Denial of Service
Impact:
Loss of Availability
Exploit:
Exploit Unavailable
Disclosure:
OSVDB Verified
Solution
Upgrade to the following versions or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.