// For flags

CVE-2012-4581

 

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not disable the server-side session token upon the closing of the Management Console/Dashboard, which makes it easier for remote attackers to hijack sessions by capturing a session cookie and then modifying the response to a login attempt, related to a "Logout Failure" issue.

McAfee Email and Web Security v5.x (EWS) antes de v5.5 Patch 6 y v5.6 antes de la revisión 3 y McAfee Email Gateway (MEG) v7.0 antes de la revisión 1 no desactivan el token de sesión en el lado del servidor durante el cierre de la Consola de administración/Cuadro de mandos, lo que hace que sea más fácil, para los atacantes remotos, el secuestrar sesiones mediante la captura de una cookie de sesión y luego modificar la respuesta a un intento de inicio de sesión. Se trata de un problema relacionado con un "Fallo de Salida".

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-08-22 CVE Reserved
  • 2012-08-22 CVE Published
  • 2024-09-17 CVE Updated
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-287: Improper Authentication
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mcafee
Search vendor "Mcafee"
Email And Web Security
Search vendor "Mcafee" for product "Email And Web Security"
5.0
Search vendor "Mcafee" for product "Email And Web Security" and version "5.0"
-
Affected
Mcafee
Search vendor "Mcafee"
Email And Web Security
Search vendor "Mcafee" for product "Email And Web Security"
5.5
Search vendor "Mcafee" for product "Email And Web Security" and version "5.5"
-
Affected
Mcafee
Search vendor "Mcafee"
Email And Web Security
Search vendor "Mcafee" for product "Email And Web Security"
5.6
Search vendor "Mcafee" for product "Email And Web Security" and version "5.6"
-
Affected
Mcafee
Search vendor "Mcafee"
Email Gateway
Search vendor "Mcafee" for product "Email Gateway"
7.0
Search vendor "Mcafee" for product "Email Gateway" and version "7.0"
-
Affected