APP: McAfee E-Business Server Authentication Remote Code Execution

This signature detects attempts to exploit a known vulnerability against McAfee E-Business Server. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the affected application.

Extended Description

McAfee E-Business Server is prone to a remote code-execution vulnerability that occurs prior to authentication. Attackers can leverage this issue to execute arbitrary code with superuser privileges. Successful exploits will completely compromise affected computers. Failed attacks will cause denial-of-service conditions. E-Business Server 8.5.2 and prior versions are vulnerable. NOTE: This issue may be related to the issue described in BID 26269 (McAfee E-Business Server Authentication Packet Handling Integer Overflow Vulnerability).

Affected Products

Mcafee e-business_server

References

BugTraq: 27197

CVE: CVE-2008-0127

Short Name
APP:MCAFEE-EBUSINESS-RCE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
Authentication CVE-2008-0127 Code E-Business Execution McAfee Remote Server bid:27197
Release Date
11/10/2012
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
Port
tcp/1718
False Positive
Unknown
Vendors

Mcafee

CVSS Score

8.8

Found a potential security threat?