// For flags

CVE-2009-3035

 

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The web console in Symantec Altiris Notification Server 6.0.x before 6.0 SP3 R12 uses a hardcoded key that can decrypt SQL Server credentials and certain discovery credentials, and stores this key on the Notification Server machine, which allows local users to obtain sensitive information and possibly execute arbitrary code by decrypting and using these credentials.

La consola web Symantec Altiris Notification Server v6.0.x anterior a v6.0 SP3 R12, usa una clave embebida que puede descifrar las credenciales del servidor SQL y otro tipo de credenciales. Almacena esta clave en la máquina Notification Server, lo que permite a usuarios locales obtener información sensible y posiblemente, ejecutar código de su elección a través de estas credenciales.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-08-31 CVE Reserved
  • 2010-02-02 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-255: Credentials Management Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Symantec
Search vendor "Symantec"
Altiris Notification Server
Search vendor "Symantec" for product "Altiris Notification Server"
6.0
Search vendor "Symantec" for product "Altiris Notification Server" and version "6.0"
-
Affected
Symantec
Search vendor "Symantec"
Altiris Notification Server
Search vendor "Symantec" for product "Altiris Notification Server"
6.0
Search vendor "Symantec" for product "Altiris Notification Server" and version "6.0"
sp1
Affected
Symantec
Search vendor "Symantec"
Altiris Notification Server
Search vendor "Symantec" for product "Altiris Notification Server"
6.0
Search vendor "Symantec" for product "Altiris Notification Server" and version "6.0"
sp2
Affected
Symantec
Search vendor "Symantec"
Altiris Notification Server
Search vendor "Symantec" for product "Altiris Notification Server"
6.0
Search vendor "Symantec" for product "Altiris Notification Server" and version "6.0"
sp3
Affected
Symantec
Search vendor "Symantec"
Altiris Notification Server
Search vendor "Symantec" for product "Altiris Notification Server"
6.0
Search vendor "Symantec" for product "Altiris Notification Server" and version "6.0"
sp3_r7
Affected
Symantec
Search vendor "Symantec"
Altiris Notification Server
Search vendor "Symantec" for product "Altiris Notification Server"
6.0
Search vendor "Symantec" for product "Altiris Notification Server" and version "6.0"
sp3_r8
Affected