First published: Wed Aug 22 2012(Updated: )
McAfee Enterprise Mobility Manager (EMM) Agent before 4.8 and Server before 10.1 record all invalid usernames presented in failed login attempts, and place them on a list of accounts that an administrator may wish to unlock, which allows remote attackers to cause a denial of service (excessive list size in the EMM Database) via a long sequence of login attempts with different usernames.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Enterprise Mobility Manager | <=4.7 | |
McAfee Enterprise Mobility Manager | <=10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4588 is categorized as a moderate severity vulnerability that could lead to a denial of service.
To remediate CVE-2012-4588, upgrade the McAfee Enterprise Mobility Manager Agent to version 4.8 or later, and the Server to version 10.1 or later.
CVE-2012-4588 affects McAfee Enterprise Mobility Manager Agent versions prior to 4.8 and Server versions prior to 10.1.
CVE-2012-4588 allows attackers to exploit the logging of invalid usernames, potentially resulting in a denial of service through excessive request handling.
Administrators can prevent exploitation of CVE-2012-4588 by ensuring their systems are updated to the latest software versions as indicated in the vulnerability report.