PT-2002-1729 · Surfcontrol · Surfcontrol Superscout Webfilter

Publicado

2002-10-03

·

Atualizado

2016-10-18

·

CVE-2002-0706

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SurfControl SuperScout WebFilter (affected versions not specified)
Description The issue concerns the use of weak encryption in the Web Reports Server for administrator functions. Specifically, the UserManager.js file uses a hard-coded key in a Javascript function, allowing remote attackers to decrypt the administrative password.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0706

Produtos afetados

Surfcontrol Superscout Webfilter