Multiple McAfee product password hash algorithm Security Vulnerability (CVE-2014-8565)
Release date:
Updated on:
Affected Systems:
McAfee FRP 4.3.0.x
McAfee EEFF 4.2.x
McAfee EEFF 4.1.x
McAfee EEFF 4.0.x
McAfee EEFF 3.2.x
Description:
Bugtraq id: 70865
CVE (CAN) ID: CVE-2014-8565
McAfee File and Removable Media Protection (FRP) is a File and folder Endpoint Encryption solution.
McAfee Endpoint Encryption for Files and Folders 3.2.x, 4.0.x, 4.1.x, 4.2.x, McAfee File and Removable Media Protection 4.3.0.x use static and predictable salt to generate password hashing, in this way, attackers can obtain user passwords through brute force guesses.
<* Source: Matthias Deeg
Link: http://seclists.org/bugtraq/2014/Oct/200
*>
Suggestion:
Vendor patch:
McAfee
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.mcafee.com/us/downloads/downloads.aspx
Https://kc.mcafee.com/corporate/index? Page = content & id = KB83095
Https://kc.mcafee.com/corporate/index? Page = content & id = SB10089
This article permanently updates the link address: