J-Security Center

Title: SurfControl SuperScout Email Filter User Credential Disclosure Vulnerability

Severity: HIGH

Description:

SurfControl SuperScout WebFilter is web filtering software for Microsoft Windows operating systems.

SurfControl SuperScout Email Filter comes with a web-based interface to provide remote access to administrative facilities.

One of the files (userlist.asp) that comes with the web interface contains a listing of administrative usernames/passwords. Users who can access this file will gain access to authentication credentials for other users.

This may allow unauthorized access to other administrative accounts, which may present a violation of security policy. Furthermore, if username and password credentials are re-used elsewhere, a malicious user may also gain access to those services.

Affected Products:

  • SurfControl SuperScout Email Filter 3.5.0
  • SurfControl SuperScout Email Filter 3.5.1
  • SurfControl SuperScout Email Filter for SMTP 4.0.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.