PT-2005-2122 · Sygate · Sygate Secure Enterprise
Mazin Faour
·
Published
2005-04-12
·
Updated
2016-10-18
·
CVE-2005-1103
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Sygate Secure Enterprise versions 3.5 through 4.1
Description
The issue allows local users to modify the security policy by exporting the policy file, changing it, and importing it back into the system, due to the lack of prevention of security policy updates by unprivileged users.
Recommendations
For Sygate Secure Enterprise versions 3.5 through 4.1, consider restricting access to the policy file to prevent unprivileged users from modifying the security policy until a fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sygate Secure Enterprise