McAfee Firewall Reporter Remote Authentication Bypass Vulnerability
RISK: High Risk
TYPE: Security software and application - Security Software & Appliance
A vulnerability has been identified in McAfee Firewall Reporter, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a design error within the "GernalUtilities.pm" script that checks for the existence of a particular file without verifying its contents while authenticating users, which could allow an attacker to bypass authentication and gain unauthorized access to the application by pointing the "cgisess" cookie value to an arbitrary file that exists on the server.
Impact
- Security Restriction Bypass
System / Technologies affected
- McAfee Firewall Reporter versions prior to 5.1.0.13
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to McAfee Firewall Reporter version 5.1.0.13 :
https://secure.mcafee.com/apps/downloads/my-products/login.aspx?region=us
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with