← Back

CVE-2012-0290

nvd nist
Published: Feb 6, 2012Modified: Apr 29, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) do not properly handle the client state after abnormal termination of a remote session, which allows remote attackers to obtain access to the client by leveraging an "open client session."

Affected (28)

3 products
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Symantec
Up to 12.5.3
Version 10.5
Version 11.5.1
Version 11.5
Version 12.1
Version 12.5.265
Version 5.0
Version 8.0
Version 9.2
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Symantec
Version 12.5.539
Version 12.5
Version 12.5 sp1
Version 12.5 sp2
Version 12.5 sp3
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Symantec
Version 12.6.65
Version 12.6.7580
Configuration D
6 vulnerable
Configuration E
6 vulnerable

Timeline

No history available yet.