Lucene search

K
cve[email protected]CVE-2012-4581
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-4581

2022-10-0316:15:34
CWE-287
web.nvd.nist.gov
18
cve-2012-4581
mcafee
email and web security
ews
mcafee email gateway
meg
session hijack
remote attack

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

6.9 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

72.9%

McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not disable the server-side session token upon the closing of the Management Console/Dashboard, which makes it easier for remote attackers to hijack sessions by capturing a session cookie and then modifying the response to a login attempt, related to a “Logout Failure” issue.

Affected configurations

NVD
Node
mcafeeemail_and_web_securityMatch5.0
OR
mcafeeemail_and_web_securityMatch5.5
OR
mcafeeemail_and_web_securityMatch5.6
OR
mcafeeemail_gatewayMatch7.0

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

6.9 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

72.9%

Related for CVE-2012-4581