Authentication Flaw in Symantec Scan Engine Allows Unauthorized Admin Access
CVE-2006-0230

Currently unrated

Key Information:

Vendor

Symantec

Vendor
CVE Published:
25 April 2006

What is CVE-2006-0230?

The Symantec Scan Engine exhibits a design flaw in its authentication mechanism, where it relies on a client-side check for password validation. This vulnerability allows remote attackers to manipulate a modified client to send specific XML requests, thereby gaining unauthorized administrator privileges. Versions prior to 5.1.0.7 are particularly susceptible, highlighting the need for updates and improved security measures.

References

EPSS Score

28% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.