Authentication Flaw in Symantec Scan Engine Allows Unauthorized Admin Access
CVE-2006-0230
Currently unrated
Summary
The Symantec Scan Engine exhibits a design flaw in its authentication mechanism, where it relies on a client-side check for password validation. This vulnerability allows remote attackers to manipulate a modified client to send specific XML requests, thereby gaining unauthorized administrator privileges. Versions prior to 5.1.0.7 are particularly susceptible, highlighting the need for updates and improved security measures.
References
EPSS Score
28% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved