McAfee Email and Web Security Appliance / Email Gateway contains a flaw related to the System Backup Password. The issue is due to the backup containing the hashed passwords of users. These can be used to conduct a brute force attack against, potentially giving access to a variety of accounts.
Classification
Location:
Remote / Network Access
Attack Type:
Cryptographic,
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Upgrade
Exploit:
Exploit Private
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Web Related,
Security Software
Solution
Upgrade Email and Web Security to version 5.5 Patch 6 or 5.6 Patch 3 or higher, and Email Gateway to version 7.0 Patch 1 or higher, as as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.