Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w95w-rvqq-jf9m

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Symantec AntiVirus Corporate Edition 9.0.1.x and 9.0.4.x, and possibly other versions, when obtaining updates from an internal LiveUpdate server, stores sensitive information in cleartext in the Log.Liveupdate log file, which allows attackers to obtain the username and password to the internal LiveUpdate server.

Symantec AntiVirus Corporate Edition 9.0.1.x and 9.0.4.x, and possibly other versions, when obtaining updates from an internal LiveUpdate server, stores sensitive information in cleartext in the Log.Liveupdate log file, which allows attackers to obtain the username and password to the internal LiveUpdate server.

EPSS

Процентиль: 24%
0.00082
Низкий

Связанные уязвимости

nvd
больше 20 лет назад

Symantec AntiVirus Corporate Edition 9.0.1.x and 9.0.4.x, and possibly other versions, when obtaining updates from an internal LiveUpdate server, stores sensitive information in cleartext in the Log.Liveupdate log file, which allows attackers to obtain the username and password to the internal LiveUpdate server.

EPSS

Процентиль: 24%
0.00082
Низкий