PT-2002-1729 · Surfcontrol · Surfcontrol Superscout Webfilter

Published

2002-10-03

·

Updated

2016-10-18

·

CVE-2002-0706

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SurfControl SuperScout WebFilter (affected versions not specified)
Description The issue concerns the use of weak encryption in the Web Reports Server for administrator functions. Specifically, the UserManager.js file uses a hard-coded key in a Javascript function, allowing remote attackers to decrypt the administrative password.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0706

Affected Products

Surfcontrol Superscout Webfilter