Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Gain a shell remotely >> NAI Management Agent overflow


Vulnerability Assessment Details

NAI Management Agent overflow

Vulnerability Assessment Summary
Acertains if the remote NAI WebShield SMTP Management trusts us

Detailed Explanation for this Vulnerability Assessment

The remote NAI WebShield SMTP Management tool
is vulnerable to a buffer overflow which permits
a possible hacker to gain execute arbitrary code
on this host when it is issued a too long argument
as a configuration parameter.

In addition to this, it permits a possible hacker to disable
the service at will.

* To re-enable the service :

- execute regedit
- edit the registry key 'Quarantine_Path' under
HKLM\SOFTWARE\Network Associates\TVD\WebShield SMTP\MailScan
- change its value from 'XXX...XXX' to the valid path to
the quarantine folder.
- restart the service

Solution : filter incoming traffic to this port. You
may also restrict the set of trusted hosts in the
configuration console :
- go to the 'server' section
- select the 'trusted clients' tab
- and set the data accordingly

Network Security Threat Level: High

Networks Security ID: 1254

Vulnerability Assessment Copyright: This script is Copyright (C) 2000 Renaud Deraison

Cables, Connectors

Cisco Catalyst 3560E 24P 1GbE 420W PoE 2P 10GbE X2 Switch WS-C3560E-24PD-S
$100.0
Cisco Catalyst 3560E 24P 1GbE 420W PoE 2P 10GbE X2 Switch WS-C3560E-24PD-S pictureCisco Catalyst 3560X WS-C3560X-48P-S V07 48Port PoE Gigabit Switch, x1 PSU (AMX)
$149.95
Cisco Catalyst 3560X WS-C3560X-48P-S V07 48Port PoE Gigabit Switch, x1 PSU (AMX) pictureNob Cisco WS-C3850-48F-S 10/100/1000 Ethernet PoE+ Port Switch
$2920.0
Nob Cisco WS-C3850-48F-S 10/100/1000 Ethernet PoE+ Port Switch  pictureWS-C3850-48U-S CISCO 48PT UPOE GE, LAN BASE, PWR-C1-1100WAC PS
$3284.89
WS-C3850-48U-S CISCO 48PT UPOE GE, LAN BASE, PWR-C1-1100WAC PS  picture


Discussions

No Discussions have been posted on this vulnerability.