5

CVE-2012-0292

Exploit

The awhost32 service in Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) allows remote attackers to cause a denial of service (daemon crash) via a crafted TCP session on port 5631.

Data is provided by the National Vulnerability Database (NVD)
SymantecPcanywhere Updatesp3 Version <= 12.5
SymantecPcanywhere Version10.0
SymantecPcanywhere Version10.5
SymantecPcanywhere Version11.0
SymantecPcanywhere Version11.0.1
SymantecPcanywhere Version11.5
SymantecPcanywhere Version11.5.1
SymantecPcanywhere Version12.0
SymantecPcanywhere Version12.0.1
SymantecPcanywhere Version12.0.2
SymantecPcanywhere Version12.0.3
SymantecPcanywhere Version12.1
SymantecPcanywhere Version12.5
SymantecPcanywhere Version12.5 Updatesp1
SymantecPcanywhere Version12.5 Updatesp2
SymantecPcanywhere Version12.5.3
SymantecPcanywhere Version12.5.265
SymantecPcanywhere Version12.5.539
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 7.22% 0.912
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.