- Description
- Symantec Altiris Deployment Solution before 6.9.164 stores the Deployment Solution Agent (aka AClient) password in cleartext in memory, which allows local users to obtain sensitive information by dumping the AClient.exe process memory.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 1.7
- Impact score
- 2.9
- Exploitability score
- 3.1
- Vector string
- AV:L/AC:L/Au:S/C:P/I:N/A:N
- nvd@nist.gov
- CWE-310
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:symantec:altiris_deployment_solution:*:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2D3DE87D-33E4-4574-AE73-26E93F57EE9C",
"versionEndIncluding": "6.8"
},
{
"criteria": "cpe:2.3:a:symantec:altiris_deployment_solution:6.8:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A1363995-0647-4C83-B3DA-360D5433DCA6"
},
{
"criteria": "cpe:2.3:a:symantec:altiris_deployment_solution:6.8.380:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "66BB840E-08C0-443A-A4B4-CAAF476AB728"
}
],
"operator": "OR"
}
]
}
]