J-Security Center

Title: Network Associates WebShield SMTP Configuration Modification Vulnerability

Severity: MODERATE

Description:

By default, Network Associates WebShield SMTP runs the management agent on port 9999. A remote user may gain access to this agent and modify the configuration of WebShield SMTP simply by connecting to this particular port. Issuing the command "GET_CONFIG<CR>" will return the current configuration. The management agent grants access based on a list of authorized hostnames, but will grant access to any IP adress which cannot be resolved to a hostname (WINS, DNS, netbios) even if 'MailCfg' is set to only allow configuration from localhost.

Affected Products:

  • Network Associates WebShield SMTP 4.5.44
  • Network Associates WebShield SMTP 4.5.74.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.