CVE-2002-2285: Medium severity Broadcom Inoculateit vulnerability
eTrust InoculateIT 6.0 with the "Incremental Scan" option enabled may certify that a file is free of viruses before the file has been completely downloaded, which allows remote attackers to bypass virus detection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the 'Incremental Scan' option in eTrust InoculateIT 6.0 to prevent files being certified as virus-free before they are fully downloaded.
eTrust InoculateIT 6.0 Incremental Scan = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2285?
CVE-2002-2285 is considered a moderate severity vulnerability due to its potential to allow remote attackers to bypass virus detection.
How do I fix CVE-2002-2285?
To mitigate CVE-2002-2285, it is advisable to disable the "Incremental Scan" option in eTrust InoculateIT 6.0.
Which versions of eTrust InoculateIT are affected by CVE-2002-2285?
CVE-2002-2285 specifically affects eTrust InoculateIT version 6.0.
What impact does CVE-2002-2285 have on eTrust InoculateIT users?
Users of eTrust InoculateIT may unknowingly download infected files, as the software may certify a file is safe before the download is complete.
Who are the potential attackers for CVE-2002-2285?
Remote attackers can exploit CVE-2002-2285 to bypass security measures, increasing the risk of malware infections.