PT-2007-5397 · Guidance · Encase Enterprise Edition
Published
2007-08-08
·
Updated
2018-10-15
·
CVE-2007-4202
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Guidance Software EnCase Enterprise Edition (EEE) version 6
Description
The issue is related to improper verification of the acquisition target's identity during communication with the EnCase Servlet, which could allow remote attackers to spoof the disk image.
Recommendations
For version 6, update the software to a version that properly verifies the identity of the acquisition target to prevent spoofing attacks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Encase Enterprise Edition