Lucene search

K
cveSymantecCVE-2013-4677
HistoryAug 05, 2013 - 1:22 p.m.

CVE-2013-4677

2013-08-0513:22:52
CWE-264
symantec
web.nvd.nist.gov
25
symantec
backup exec
weak permissions
security vulnerability
nvd

CVSS2

4.3

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:S/C:P/I:P/A:P

AI Score

6

Confidence

Low

EPSS

0

Percentile

9.5%

Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 uses weak permissions (Everyone: Read and Everyone: Change) for backup data files, which allows local users to obtain sensitive information or modify the outcome of a restore via direct access to these files.

Affected configurations

Nvd
Node
symantecbackup_execMatch2010
OR
symantecbackup_execMatch2010_r3sp1
OR
symantecbackup_execMatch2010_r3sp2
OR
symantecbackup_execMatch2012
OR
symantecbackup_execMatch2012sp1
VendorProductVersionCPE
symantecbackup_exec2010cpe:2.3:a:symantec:backup_exec:2010:*:*:*:*:*:*:*
symantecbackup_exec2010_r3cpe:2.3:a:symantec:backup_exec:2010_r3:sp1:*:*:*:*:*:*
symantecbackup_exec2010_r3cpe:2.3:a:symantec:backup_exec:2010_r3:sp2:*:*:*:*:*:*
symantecbackup_exec2012cpe:2.3:a:symantec:backup_exec:2012:*:*:*:*:*:*:*
symantecbackup_exec2012cpe:2.3:a:symantec:backup_exec:2012:sp1:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:S/C:P/I:P/A:P

AI Score

6

Confidence

Low

EPSS

0

Percentile

9.5%

Related for CVE-2013-4677