First published: Fri Jul 10 2009(Updated: )
SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in admin_backup.xml files and uses insecure permissions for these files, which allows local users to gain privileges. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee SmartFilter | =4.2.1.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2429 is considered a high severity vulnerability due to the risk of privilege escalation from improperly secured credentials.
To fix CVE-2009-2429, ensure that sensitive files like admin_backup.xml are deleted or secured with proper permissions, and consider upgrading to a more secure version of SmartFilter.
CVE-2009-2429 affects McAfee SmartFilter version 4.2.1.00.
The risks associated with CVE-2009-2429 include unauthorized access to admin credentials, which can lead to system compromise and privilege escalation.
Local users with access to the system can be impacted by CVE-2009-2429 as they can potentially exploit the cleartext storage of credentials.