10

CVE-2012-0290

Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) do not properly handle the client state after abnormal termination of a remote session, which allows remote attackers to obtain access to the client by leveraging an "open client session."

Data is provided by the National Vulnerability Database (NVD)
SymantecPcanywhere Version <= 12.5.3
SymantecPcanywhere Version5.0
SymantecPcanywhere Version8.0
SymantecPcanywhere Version9.2
SymantecPcanywhere Version10.5
SymantecPcanywhere Version11.5
SymantecPcanywhere Version11.5.1
SymantecPcanywhere Version12.1
SymantecPcanywhere Version12.5 Updatesp1
SymantecPcanywhere Version12.5 Updatesp2
SymantecPcanywhere Version12.5 Updatesp3
SymantecPcanywhere Version12.5.265
SymantecPcanywhere Version12.5
SymantecPcanywhere Version12.5 Updatesp1
SymantecPcanywhere Version12.5 Updatesp2
SymantecPcanywhere Version12.5 Updatesp3
SymantecPcanywhere Version12.5.539
SymantecPcanywhere Version12.6.65
SymantecPcanywhere Version12.6.7580
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.61% 0.843
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C