Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2007-3022


Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, displays the password hash for a user after a failed login attempt, which makes it easier for remote attackers to conduct brute force attacks.


Published

2007-06-05T21:30:00.000

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application symantec client_security 3.1 Yes
Application symantec client_security 3.1.394 Yes
Application symantec client_security 3.1.396 Yes
Application symantec client_security 3.1.400 Yes
Application symantec client_security 3.1.401 Yes
Application symantec norton_antivirus 10.0.2.2021 Yes
Application symantec norton_antivirus 10.1 Yes
Application symantec norton_antivirus 10.1.396 Yes
Application symantec norton_antivirus 10.1.400 Yes
Application symantec norton_antivirus 10.1.401 Yes
Application symantec reporting_server ≤ 1.0.197.0 Yes

References