>> Symantec Scan Engine Authentication Bypass and Information Disclosure Issues
Title : Symantec Scan Engine Authentication Bypass and Information Disclosure Issues VUPEN ID : VUPEN/ADV-2006-1464 CVE ID : CVE-2006-0230 - CVE-2006-0231 - CVE-2006-0232
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-04-22
Technical Description
Multiple vulnerabilities have been identified in Symantec Scan Engine, which could be exploited by attackers to gain unauthorized access to a vulnerable application.
The first flaw is due to a design error in the underlying communication and authentication mechanism used by the web-based administrative interface (ports 8004 and 8005), which could be exploited by remote attackers to bypass security restrictions and gain administrative access to a vulnerable server.
The second flaw is due to a design error where the application uses a static private DSA key for SSL communications, which could be exploited by malicious people to conduct man-in-the-middle attacks.
The third vulnerability is due to an error in the HTTP server (port 8004) that does not properly restrict access to files located under the installation directory, which could be exploited by unauthenticated remote attackers to download the configuration file, the scanning logs, and the current virus definitions.