Altiris Deployment Solution Server < 6.9.355 Password Disclosure (SYM08-020) (deprecated)

medium Nessus Network Monitor Plugin ID 4772

Synopsis

The remote Windows host has a program that is affected by a password disclosure vulnerability.

Description

The version of the Altiris Deployment Solution installed on the remote host is reportedly affected by a password disclosure vulnerability. Altiris Deployment Solution Server reportedly stores 'Application Identity Account password' in the system memory in plaintext. It may be possible for an authorized non-privileged user to retrieve this password and make unauthorized modifications to the client systems. The level of unauthorized access depends on the user group under which Application Identity Account was registered during installation.

Solution

Upgrade to version 6.9 Build 355 or higher.

See Also

http://www.symantec.com/avcenter/security/Content/2008.10.20b.html

Plugin Details

Severity: Medium

ID: 4772

Family: Generic

Published: 12/1/2008

Updated: 3/6/2019

Nessus ID: 34964

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Reference Information

CVE: CVE-2008-6828

BID: 31767