US-CERT is now warning against a potentially dangerous flaw in the SSL-VPN implementations from over two dozen vendors including industry giant Cisco. "
Clientless SSL VPN products from multiple vendors operate in a way that breaks fundamental browser security mechanisms," US-CERT warns. "An attacker could use these devices to bypass authentication or conduct other Web-based attacks."...