Vulnerabilities > CVE-2009-2429 - Credentials Management vulnerability in Mcafee Smartfilter 4.2.1.00

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
mcafee
CWE-255

Summary

SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in admin_backup.xml files and uses insecure permissions for these files, which allows local users to gain privileges. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Vulnerable Configurations

Part Description Count
Application
Mcafee
1

Common Weakness Enumeration (CWE)

Seebug

bulletinFamilyexploit
descriptionBugraq ID: 35756 CVE ID:CVE-2009-2312 CVE-2009-2429 CNCVE ID:CNCVE-20092312 CNCVE-20092429 McAfee SmartFilter是一款网站过滤解决方案。 McAfee SmartFilter存在设计问题,本地攻击者可以利用漏洞获得敏感信息。 用于proxy服务器验证的SmartFilter user ID的用户名和明文文本密码保存在c:\Program Files\Secure Computing\Smartfilter Administration\server目录下的config子目录中,利用这些敏感信息可对系统进行进一步攻击。 0 McAfee SmartFilter 4.2.1.00 厂商解决方案 目前没有解决方案提供: http://www.securecomputing.com/
idSSV:11863
last seen2017-11-19
modified2009-07-23
published2009-07-23
reporterRoot
titleMcAfee SmartFilter信息泄漏漏洞