Title: SnortCenter Insecure Sensor Configuration File Permissions Vulnerability
Severity: MODERATE
Description:
SnortCenter is a web-based client-server management system written in PHP and Perl. It assists in the configuration of Snort configuration and signature files.
A vulnerability has been discovered in SnortCenter v0.9.5
When SnortCenter is used to aggregate Snort rules for a particular sensor, a file is created in the /tmp directory which are 'world' accessible. The temporary sensor configuration files created may contain sensitive alert database server access credentials.
Information disclosed by accessing this file may aid a malicious user in launching attacks against alert database servers. The ability to modify sensitive information contained within these files may result in the corruption of typical SnortCenter functionality.
Affected Products:
- SnortCenter SnortCenter 0.9.5
References:
- SnortCenter: SnortCenter Product Page
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.