Vulnerability Name: | CVE-2009-3035 (CCN-55952) | ||||||||
Assigned: | 2009-08-31 | ||||||||
Published: | 2010-01-28 | ||||||||
Updated: | 2017-08-17 | ||||||||
Summary: | The web console in Symantec Altiris Notification Server 6.0.x before 6.0 SP3 R12 uses a hardcoded key that can decrypt SQL Server credentials and certain discovery credentials, and stores this key on the Notification Server machine, which allows local users to obtain sensitive information and possibly execute arbitrary code by decrypting and using these credentials. | ||||||||
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:P/A:P) 3.2 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-255 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-3035 Source: OSVDB Type: UNKNOWN 62010 Source: CCN Type: SA38356 Symantec Altiris Notification Server Static Encryption Key Source: SECUNIA Type: Vendor Advisory 38356 Source: CCN Type: SECTRACK ID: 1023521 Symantec Altiris Notification Server Lets Local Users Access Authenticated Credentials Source: CCN Type: OSVDB ID: 62010 Symantec Altiris Notification Server Static Encryption Key Weakness Credentials Disclosure Source: BID Type: UNKNOWN 37953 Source: CCN Type: BID-37953 Symantec Altiris Notification Server Static Encryption Key Unauthorized Access Vulnerability Source: SECTRACK Type: UNKNOWN 1023521 Source: CCN Type: SYM10-001 Symantec Altiris Notification Server 6.x Static Encryption Key Source: CONFIRM Type: UNKNOWN http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100128_00 Source: VUPEN Type: UNKNOWN ADV-2010-0256 Source: XF Type: UNKNOWN symantec-ans-key-unauth-access(55952) Source: XF Type: UNKNOWN symantec-ans-key-unauth-access(55952) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |