CVE-2009-3035
Last modified
CVE-2009-3035 is a vulnerability of currently unknown severity. The web console in Symantec Altiris Notification Server 6.0.x before 6.0 SP3 R12 uses a hardcoded key that can decrypt SQL Server credentials and certain discovery credentials, and stores this key on the Notification Server machine, which allows local users to obtain sensitive information and possibly execute arbitrary code by decrypting and using these credentials.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
The web console in Symantec Altiris Notification Server 6.0.x before 6.0 SP3 R12 uses a hardcoded key that can decrypt SQL Server credentials and certain discovery credentials, and stores this key on the Notification Server machine, which allows local users to obtain sensitive information and possibly execute arbitrary code by decrypting and using these credentials.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Symantec | Altiris Notification Server | 6.0 |
References
- http://secunia.com/advisories/38356Vendor Advisory
- http://secunia.com/advisories/38356Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-3035?
How severe is CVE-2009-3035?
How do I fix CVE-2009-3035?
Are you affected by CVE-2009-3035?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
