ID

VAR-200005-0111


TITLE

WebShield SMTP 4.5.44 Buffer Overflow Vulnerability

Trust: 1.0

sources: IVD: 7d71450f-463f-11e9-b4bc-000c29342cb1 // IVD: c91180a8-2080-11e6-abef-000c29c66e3d // CNVD: CNVD-2000-0544

DESCRIPTION

The listening port of the Network Associates WebShield SMTP 4.5.44 remote management service is 9999. When connected to this port, you can get the current configuration by executing the following command: GET_CONFIG & lt; CR> When accepting a string of more than 208 bytes to When parameters are configured, a stack overflow occurs. This service usually crashes. If the string contains executable code, an attacker may execute arbitrary commands as system. & lt; * Source: Delphis Consulting Plc Security Team Advisories securityteam@delphisplc.com *>

Trust: 0.9

sources: CNVD: CNVD-2000-0544 // IVD: 7d71450f-463f-11e9-b4bc-000c29342cb1 // IVD: c91180a8-2080-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 1.0

sources: IVD: 7d71450f-463f-11e9-b4bc-000c29342cb1 // IVD: c91180a8-2080-11e6-abef-000c29c66e3d // CNVD: CNVD-2000-0544

AFFECTED PRODUCTS

vendor:nonemodel: - scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2000-0544

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 7d71450f-463f-11e9-b4bc-000c29342cb1
value: HIGH

Trust: 0.2

IVD: c91180a8-2080-11e6-abef-000c29c66e3d
value: LOW

Trust: 0.2

IVD: 7d71450f-463f-11e9-b4bc-000c29342cb1
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

IVD: c91180a8-2080-11e6-abef-000c29c66e3d
severity: NONE
baseScore: NONE
vectorString: NONE
accessVector: NONE
accessComplexity: NONE
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: UNKNOWN

Trust: 0.2

sources: IVD: 7d71450f-463f-11e9-b4bc-000c29342cb1 // IVD: c91180a8-2080-11e6-abef-000c29c66e3d

TYPE

Buffer overflow

Trust: 0.4

sources: IVD: 7d71450f-463f-11e9-b4bc-000c29342cb1 // IVD: c91180a8-2080-11e6-abef-000c29c66e3d

EXTERNAL IDS

db:CNVDid:CNVD-2000-0544

Trust: 1.0

db:IVDid:7D71450F-463F-11E9-B4BC-000C29342CB1

Trust: 0.2

db:IVDid:C91180A8-2080-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 7d71450f-463f-11e9-b4bc-000c29342cb1 // IVD: c91180a8-2080-11e6-abef-000c29c66e3d // CNVD: CNVD-2000-0544

SOURCES

db:IVDid:7d71450f-463f-11e9-b4bc-000c29342cb1
db:IVDid:c91180a8-2080-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2000-0544

LAST UPDATE DATE

2022-05-17T01:42:55.405000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2000-0544date:2000-05-29T00:00:00

SOURCES RELEASE DATE

db:IVDid:7d71450f-463f-11e9-b4bc-000c29342cb1date:2000-05-29T00:00:00
db:IVDid:c91180a8-2080-11e6-abef-000c29c66e3ddate:2000-05-29T00:00:00
db:CNVDid:CNVD-2000-0544date:2000-05-29T00:00:00