JMH
Emeritus, Contributor
- Apr 2, 2012
- 7,197
Intel Security Product Had Backdoor Account That Granted Access Regardless of Password
Intel Security Product Had Backdoor Account That Granted Access Regardless of PasswordIntel Security has patched a critical vulnerability in the Enterprise Security Manager, part of the McAfee line of security products.
The McAfee Enterprise Security Manager (codenamed SIEM ESM) is a powerful threat detection and analysis system developed by McAfee, prior to being acquired by Intel and the company being rebranded into Intel Security.
SIEM ESM is commonly found in larger enterprises, helping sysadmins protect their networks against a wide range of attack types.
Attackers can log in as admins without the correct password
According to research carried out by QuantumLeap, the McAfee Enterprise Security Manager is vulnerable to a simple-to-exploit authentication bypass vulnerability.