Authentication Flaw in Symantec Scan Engine Allows Unauthorized Admin Access
CVE-2006-0230

Currently unrated

Key Information:

Vendor
Symantec
Vendor
CVE Published:
25 April 2006

Summary

The Symantec Scan Engine exhibits a design flaw in its authentication mechanism, where it relies on a client-side check for password validation. This vulnerability allows remote attackers to manipulate a modified client to send specific XML requests, thereby gaining unauthorized administrator privileges. Versions prior to 5.1.0.7 are particularly susceptible, highlighting the need for updates and improved security measures.

References

EPSS Score

28% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.