4.3

CVE-2013-4677

Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 uses weak permissions (Everyone: Read and Everyone: Change) for backup data files, which allows local users to obtain sensitive information or modify the outcome of a restore via direct access to these files.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SymantecBackup Exec Version2010
SymantecBackup Exec Version2010_r3 Updatesp1
SymantecBackup Exec Version2010_r3 Updatesp2
SymantecBackup Exec Version2012
SymantecBackup Exec Version2012 Updatesp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.13
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 3.1 6.4
AV:L/AC:L/Au:S/C:P/I:P/A:P