CVE Vulnerabilities

CVE-2007-3022

Published: Jun 05, 2007 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, displays the password hash for a user after a failed login attempt, which makes it easier for remote attackers to conduct brute force attacks.

Affected Software

Name Vendor Start Version End Version
Client_security Symantec 3.1 (including) 3.1 (including)
Client_security Symantec 3.1.394 (including) 3.1.394 (including)
Client_security Symantec 3.1.396 (including) 3.1.396 (including)
Client_security Symantec 3.1.400 (including) 3.1.400 (including)
Client_security Symantec 3.1.401 (including) 3.1.401 (including)
Norton_antivirus Symantec 10.0.2.2021 (including) 10.0.2.2021 (including)
Norton_antivirus Symantec 10.1 (including) 10.1 (including)
Norton_antivirus Symantec 10.1.396 (including) 10.1.396 (including)
Norton_antivirus Symantec 10.1.400 (including) 10.1.400 (including)
Norton_antivirus Symantec 10.1.401 (including) 10.1.401 (including)
Reporting_server Symantec * 1.0.197.0 (including)

References