NetScout Administrator 'add_domain.jsp' Authentication Bypass Vulnerability
BID:29590
Info
NetScout Administrator 'add_domain.jsp' Authentication Bypass Vulnerability
| Bugtraq ID: | 29590 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-6701 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 06 2008 12:00AM |
| Updated: | Jun 06 2008 12:00AM |
| Credit: | jgrove_2000 |
| Vulnerable: |
NetScout Administrator 0 |
| Not Vulnerable: | |
Discussion
NetScout Administrator 'add_domain.jsp' Authentication Bypass Vulnerability
NetScout Administrator is prone to a vulnerability that allows attackers to access a privileged script without authorization.
Attackers can exploit this issue to perform unauthorized administrative functions. This can aid in further attacks.
The NetScout Administrator device is vulnerable; other devices may also be affected.
Reports indicated that this issue may exist in Network General Visualizer V2100 and Network General Infinistream i1730 Sniffer. This has not been confirmed.
NetScout Administrator is prone to a vulnerability that allows attackers to access a privileged script without authorization.
Attackers can exploit this issue to perform unauthorized administrative functions. This can aid in further attacks.
The NetScout Administrator device is vulnerable; other devices may also be affected.
Reports indicated that this issue may exist in Network General Visualizer V2100 and Network General Infinistream i1730 Sniffer. This has not been confirmed.
Exploit / POC
NetScout Administrator 'add_domain.jsp' Authentication Bypass Vulnerability
Attackers can leverage this issue with a browser.
Attackers can leverage this issue with a browser.
Solution / Fix
NetScout Administrator 'add_domain.jsp' Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
NetScout Administrator 'add_domain.jsp' Authentication Bypass Vulnerability
References:
References: