CVE-2006-3785
Last modified
CVE-2006-3785 is a vulnerability of currently unknown severity. Symantec pcAnywhere 12.5 obfuscates the passwords in a GUI textbox with asterisks but does not encrypt them in the associated .cif (aka caller or CallerID) file, which allows local users to obtain the passwords from the window using tools such as Nirsoft Asterwin.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
Symantec pcAnywhere 12.5 obfuscates the passwords in a GUI textbox with asterisks but does not encrypt them in the associated .cif (aka caller or CallerID) file, which allows local users to obtain the passwords from the window using tools such as Nirsoft Asterwin.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Symantec | Pcanywhere | 12.5 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-3785?
How severe is CVE-2006-3785?
How do I fix CVE-2006-3785?
Are you affected by CVE-2006-3785?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
