CVE-2009-3110
Published Sep 8, 2009
Last updated 12 years ago
Overview
- Description
- Race condition in the file transfer functionality in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 allows remote attackers to read sensitive files and prevent client updates by connecting to the file transfer port before the expected client does.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5.8
- Impact score
- 4.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:N/A:P
Weaknesses
- nvd@nist.gov
- CWE-362
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:symantec:altiris_deployment_solution:6.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F0002047-0965-4086-A5E6-AEC02200B6CF" }, { "criteria": "cpe:2.3:a:symantec:altiris_deployment_solution:6.9:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EBD29C7F-B147-4CDE-8AC3-FCA6CA15C464" }, { "criteria": "cpe:2.3:a:symantec:altiris_deployment_solution:6.9.164:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BA744B2A-B81E-4E97-A720-307041478B97" }, { "criteria": "cpe:2.3:a:symantec:altiris_deployment_solution:6.9.176:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E9301CFC-5925-4249-8439-5E2BBAF06687" }, { "criteria": "cpe:2.3:a:symantec:altiris_deployment_solution:6.9.355:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E4070F9F-F63E-4708-8DA0-339A777383B4" }, { "criteria": "cpe:2.3:a:symantec:altiris_deployment_solution:6.9.355:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5C9DD5AC-7E4C-4A62-A5B3-B179359635A1" } ], "operator": "OR" } ] } ]