PT-2007-5397 · Guidance · Encase Enterprise Edition

Published

2007-08-08

·

Updated

2018-10-15

·

CVE-2007-4202

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Guidance Software EnCase Enterprise Edition (EEE) version 6
Description The issue is related to improper verification of the acquisition target's identity during communication with the EnCase Servlet, which could allow remote attackers to spoof the disk image.
Recommendations For version 6, update the software to a version that properly verifies the identity of the acquisition target to prevent spoofing attacks.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-4202

Affected Products

Encase Enterprise Edition