SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-3107

Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 does not properly restrict access to the listening port for the DBManager service, which allows remote attackers to bypass authentication and modify tasks or the Altiris Database via a…

MEDIUM 4.8EPSS 0.97%

Does this matter?

Lower severity and a low EPSS score (0.97%). Track it; it rarely justifies an emergency change on its own.

Description

Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 does not properly restrict access to the listening port for the DBManager service, which allows remote attackers to bypass authentication and modify tasks or the Altiris Database via a connection to this service.

CVSS 2.0
4.8 MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:N
EPSS
0.97% probability · 60th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
symantec/altiris deployment solution
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.