-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2015.0033
           Three vulnerabilities have been identified in McAfee
                          Advanced Threat Defense
                               13 April 2015

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              McAfee Advanced Threat Defense
Operating System:     Network Appliance
Impact/Access:        Administrator Compromise -- Existing Account
                      Access Confidential Data -- Existing Account
Resolution:           Patch/Upgrade
Member content until: Wednesday, May 13 2015

OVERVIEW

        Three vulnerabilities have been identified in McAfee Advanced Threat
        Defense prior to version 3.4.4.63. [1]


IMPACT

        The vendor has provided the following details regarding these 
        issues:
        
        "1. Configuration Information: The MATD appliance web interface is 
        showing configuration information in plain text format.
        
        2. Authentication Enforcement: The MATD web interface has loose 
        enforcement of authentication and authorization which leads to 
        information disclosure.
        
        3. Privilege Escalation: The MATD appliance allows the administrator
        only to change/update any configuration settings, but in some 
        instances an unprivileged user can manipulate some parameters to 
        gain administrator functionality." [1]


MITIGATION

        The vendor recommends updating to the latest version of McAfee 
        Advanced Threat Defense to correct these issues. [1]


REFERENCES

        [1] Intel Security Security Bulletin - Advanced Threat Defense update
            patches three vulnerabilities
            https://kc.mcafee.com/corporate/index?page=content&id=SB10112

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBVSskqRLndAQH1ShLAQIzbA//XoBbv0lK3xrwAZk4YfWmdc1JmqF/OJ6k
4Tjz8Mx0hAcJWW25HjUsLJvoOJotI8eeNmGsGALJmR7FYNMjEMszeQQ38MthmZJh
gtAi1akoaownNxulCd9oznPROL9r25yrgTzEwxT6grIxv2yWzPNWUECXoPRK5V/3
fQwH62zKFFmwCXBbuespNK9JMY1Y3TcP/MnKcahTzUAh4BUPjuW/zg+66PCYy5jE
VZkF98cUWyf864n9Z+30hcDvC71FnaTwJSigTNXb1T0IV+CdqLM1CoHMVcjoC6eo
c5QAY6on5BVcxShT2VIs2CPJHV1ViwYF+LfW5l9u7XdaEsC7d7FvcPTdRAtL6tJF
QEmBKtunLuywnqfyNSRnus50MW00UwzFHEGqOtw1Aguqi0dU+YDOCnx2MRn7rTiw
cA/pcerlo5CI003PPY9ExvNNOFKlLx3lTScaAHNPwCd9bS4lW7QekTrZME/4pgZ7
Czg5mt1FP4Mrz40ElZo7kcWZGDhyQR57Xx8u7s1btO604bUS44ErFVfz8PG8zAMy
BTOYyBOfFTPlUl/uMTeQnYKBeMekhmiL4ecnps668yHHhpsnfq112f8Z8nA0MxfW
jegJvohFugcS3FLKPhVnzh9MGoX0zSv+jgs1CEfMSyDww+NAP2qbr5m/MEUIo1W7
phWW8ove7U0=
=b9fG
-----END PGP SIGNATURE-----