Check Point Reference: | CPAI-2011-339 |
Date Published: | 19 Jul 2011 |
Severity: | Critical |
Last Updated: | Tuesday 19 July, 2011 |
Source: | |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | |
Vulnerability Description | An authentication bypass vulnerability has been reported in McAfee Firewall Reporter. The vulnerability is due to a design flaw in the way that McAfee Firewall Reporter validates session IDs while authenticating users. Remote attackers could trigger this flaw by connecting to a vulnerable McAfee web interface and sending a specially crafted malicious HTTP request. |
This protection will detect and block malicious HTTP requests sent to the vulnerable server.
In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.
This protection's log will contain the following information:
Attack Name: Security Products Enforcement Violation.
Attack Information: McAfee Firewall Reporter isValidClient remote code execution