PT-2006-2300 · Symantec+1 · Symantec Ghost Solution Suite+2
Published
2006-03-19
·
Updated
2011-03-08
·
CVE-2006-1284
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Symantec Ghost Solutions Suite (SGSS) version 1.0
Symantec Ghost version 8.0
Symantec Ghost version 8.2
Description
The issue concerns the installation of SQLAnywhere in Symantec Ghost, which includes a default administrator login account and password. This allows local users to gain privileges or modify tasks.
Recommendations
For Symantec Ghost Solutions Suite (SGSS) version 1.0, change the default administrator login account and password to prevent unauthorized access.
For Symantec Ghost version 8.0, update the default administrator login account and password to secure the system.
For Symantec Ghost version 8.2, modify the default administrator login account and password to prevent privilege escalation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sqlanywhere
Symantec Ghost
Symantec Ghost Solution Suite