PT-2006-4645 · Symantec+1 · Symantec Pcanywhere+1

Root

·

Publicado

2006-07-21

·

Atualizado

2018-10-17

·

CVE-2006-3785

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Symantec pcAnywhere version 12.5
Description The issue allows local users to obtain passwords from a window using certain tools, such as Nirsoft Asterwin, because the passwords are not encrypted in the associated .cif file, despite being obfuscated with asterisks in a GUI textbox.
Recommendations For Symantec pcAnywhere version 12.5, consider restricting access to the .cif file to minimize the risk of password exposure until a proper fix is available. As a temporary workaround, avoid storing sensitive passwords in the GUI textbox.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-3785

Produtos afetados

Nirsoft Asterwin
Symantec Pcanywhere