NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Advisories

Advisories


Symantec Firewall - The Pick-Me-Although-I'm-Buggy Solution!

Security flaw discovered in Symantec Enterprise Firewall

By Bogdan Popa, Security and Search Engines Editor

17th of August 2007, 09:40 GMT

Adjust text size:



Enlarge picture
Symantec Enterprise Firewall, a security solution that was meant to represent the protection system for the enterprise consumers, is now vulnerable to attacks as a new flaw was discovered. Security company Secunia discovered the hole that might allow an attacker to obtain valid usernames
from the affected computer but rated it as not critical. The vulnerability was already confirmed in Symantec Enterprise 6.x but there is no official statement that it might affect the previous versions of the product.

"A weakness has been reported in Symantec Enterprise Firewall, which can be exploited by malicious people to determine valid usernames. The problem is that a different response is sent when using a valid or invalid username and can be exploited to determine valid usernames. Successful exploitation requires that the application is configured for remote access (client-to-gateway) VPN using pre-shared key (PSK) authentication," Secunia mentioned in the advisory.

Symantec confirmed the vulnerability and added that the exposure can provide instant access to usernames and passwords through a login interface. The severity of the hole was low but Symantec encourages users to apply the solution as soon as possible.

"Symantec engineers have verified this exposure. They have found that if the Client VPN is configured with a username "default-ikeuser", the problem disappears. This user name is used to enable off-box extended authentication. Off-box extended authentication however is not need to add the default-ikeuser to any group that has firewall rules associated with it," Symantec mentioned in the message posted today on the official page of the company.

In the recent period, Symantec was one of the most affected firms when it comes to vulnerable security products but numerous consumers are continuously looking for their solutions. If you want to download a Symantec product, you can find all of them listed on Softpedia.

TAGS:

symantec | security | flaw | vulnerability
Read by 922 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.7/5) 7 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Oh No, Norton Antivirus Is Once Again Dangerous for My PC!

New Symantec Security Solution Hits the Web

The Symantec Employees Are Using Kaspersky!

Symantec Offers Free Licenses

Norton Firewall Gets Vulnerable One More Time

Symantec Exposes Windows Vista

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM