Description: Ingate has acknowledged a vulnerability in their Ingate Firewall and SIParator products, which can be exploited by malicious people to bypass certain security restrictions.
Note: This affects only systems using SIP over TLS and where a X.509 certificate uses an RSA key with exponent 3. The Ingate product does not create such keys.
Solution: Contact the vendor for a patch for this issue.
The vendor recommends to use a CA that don't use RSA keys with exponent 3 or to turn off the SIP module if that is not possible.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.