Symantec Messaging Gateway SSH Default Password Security Bypass Vulnerability
BID:55143
Info
Symantec Messaging Gateway SSH Default Password Security Bypass Vulnerability
| Bugtraq ID: | 55143 |
| Class: | Design Error |
| CVE: |
CVE-2012-3579 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 27 2012 12:00AM |
| Updated: | Sep 07 2012 11:10AM |
| Credit: | Stefan Viehböck with SEC Consulting |
| Vulnerable: |
Symantec Messaging Gateway 9.5.1 Symantec Messaging Gateway 9.5 |
| Not Vulnerable: | |
Discussion
Symantec Messaging Gateway SSH Default Password Security Bypass Vulnerability
Symantec Messaging Gateway is prone to a security-bypass vulnerability.
Successful attacks can allow an attacker to gain privileged access to the affected application using the default authentication credentials. Successful attacks can allow an attacker to obtain sensitive information, bypass certain security restrictions, and perform unauthorized administrative actions.
Symantec Messaging Gateway 9.5.x versions are vulnerable.
Symantec Messaging Gateway is prone to a security-bypass vulnerability.
Successful attacks can allow an attacker to gain privileged access to the affected application using the default authentication credentials. Successful attacks can allow an attacker to obtain sensitive information, bypass certain security restrictions, and perform unauthorized administrative actions.
Symantec Messaging Gateway 9.5.x versions are vulnerable.
Exploit / POC
Symantec Messaging Gateway SSH Default Password Security Bypass Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Symantec Messaging Gateway SSH Default Password Security Bypass Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Symantec Messaging Gateway SSH Default Password Security Bypass Vulnerability
References:
References: