VulnerabilityModified
CVE-2009-2312
SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in config.txt and uses insecure permissions for this file, which allows local users to gain privileges.
MEDIUM 4.6EPSS 0.29%
Does this matter?
Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.
Description
SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in config.txt and uses insecure permissions for this file, which allows local users to gain privileges.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.29% probability · 22th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- mcafee/smartfilter
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2009-03/0314.html
- http://secunia.com/advisories/34390Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49338
- http://archives.neohapsis.com/archives/fulldisclosure/2009-03/0314.html
- http://secunia.com/advisories/34390Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49338
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.