CVE-2012-0290
Summary
| CVE | CVE-2012-0290 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-02-06 20:55:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) do not properly handle the client state after abnormal termination of a remote session, which allows remote attackers to obtain access to the client by leveraging an "open client session." |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec | Pcanywhere | 10.5 | All | All | All |
| Application | Symantec | Pcanywhere | 11.5 | All | All | All |
| Application | Symantec | Pcanywhere | 11.5.1 | All | All | All |
| Application | Symantec | Pcanywhere | 12.1 | All | All | All |
| Application | Symantec | Pcanywhere | 12.5 | All | All | All |
| Application | Symantec | Pcanywhere | 12.5 | sp1 | All | All |
| Application | Symantec | Pcanywhere | 12.5 | sp2 | All | All |
| Application | Symantec | Pcanywhere | 12.5 | sp3 | All | All |
| Application | Symantec | Pcanywhere | 12.5.265 | All | All | All |
| Application | Symantec | Pcanywhere | 5.0 | All | All | All |
| Application | Symantec | Pcanywhere | 8.0 | All | All | All |
| Application | Symantec | Pcanywhere | 9.2 | All | All | All |
| Application | Symantec | Pcanywhere | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisories Relating to Symantec Products - Symantec pcAnywhere Multiple Security Updates - 2012-01-24T12:49:40 PST | Symantec | af854a3a-2127-422b-91ae-364da2661108 | www.symantec.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Symantec pcAnywhere Session Closure Access Violation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.