First published: Thu Jul 02 2009(Updated: )
SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in config.txt and uses insecure permissions for this file, which allows local users to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee SmartFilter | =4.2.1.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2312 is considered a high severity vulnerability due to sensitive user credentials being stored in cleartext.
To fix CVE-2009-2312, ensure that user credentials are not stored in cleartext and restrict access permissions for the config.txt file.
The consequences of CVE-2009-2312 include potential privilege escalation for local users exploiting the cleartext storage of credentials.
CVE-2009-2312 specifically affects McAfee SmartFilter version 4.2.1.00.
Local users can exploit CVE-2009-2312 by accessing the config.txt file to retrieve cleartext credentials, allowing them to gain privileged access.