4.3

CVE-2013-4677

Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 uses weak permissions (Everyone: Read and Everyone: Change) for backup data files, which allows local users to obtain sensitive information or modify the outcome of a restore via direct access to these files.

Data is provided by the National Vulnerability Database (NVD)
SymantecBackup Exec Version2010
SymantecBackup Exec Version2010_r3 Updatesp1
SymantecBackup Exec Version2010_r3 Updatesp2
SymantecBackup Exec Version2012
SymantecBackup Exec Version2012 Updatesp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.13
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 3.1 6.4
AV:L/AC:L/Au:S/C:P/I:P/A:P