PT-2007-5397 · Guidance · Encase Enterprise Edition
Publicado
2007-08-08
·
Atualizado
2018-10-15
·
CVE-2007-4202
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Guidance Software EnCase Enterprise Edition (EEE) version 6
Description
The issue is related to improper verification of the acquisition target's identity during communication with the EnCase Servlet, which could allow remote attackers to spoof the disk image.
Recommendations
For version 6, update the software to a version that properly verifies the identity of the acquisition target to prevent spoofing attacks.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Encase Enterprise Edition