{"api_version":"1","generated_at":"2026-07-23T10:42:36+00:00","cve":"CVE-2005-3316","urls":{"html":"https://cve.report/CVE-2005-3316","api":"https://cve.report/api/cve/CVE-2005-3316.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3316","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3316"},"summary":{"title":"CVE-2005-3316","description":"The installation of ON Symantec Discovery 4.5.x and Symantec Discovery 6.0 creates the (1) DiscoveryWeb and (2) DiscoveryRO database accounts with null passwords, which could allow attackers to gain privileges or prevent Discovery from running by setting another password.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-10-27 10:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://securityreason.com/securityalert/112","name":"http://securityreason.com/securityalert/112","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Discovery Web Accounts Null Password - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/17302","name":"http://secunia.com/advisories/17302","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - Symantec Discovery Database Accounts Null Password","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/15188","name":"http://www.securityfocus.com/bid/15188","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Discovery Web Accounts Default Password Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securityresponse.symantec.com/avcenter/security/Content/2005.10.24.html","name":"http://securityresponse.symantec.com/avcenter/security/Content/2005.10.24.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Discovery Web Accounts Null Password","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1015097","name":"http://securitytracker.com/id?1015097","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Symantec Discovery Creates Database Accounts Without Passwords","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3316","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3316","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3316","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"discovery","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"3316","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"on_command_discovery","cpe6":"standard_4.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"3316","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"on_command_discovery","cpe6":"web_4.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:10:07.588Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://securityresponse.symantec.com/avcenter/security/Content/2005.10.24.html"},{"name":"1015097","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015097"},{"name":"112","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/112"},{"name":"15188","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15188"},{"name":"17302","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17302"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-10-24T00:00:00.000Z","descriptions":[{"lang":"en","value":"The installation of ON Symantec Discovery 4.5.x and Symantec Discovery 6.0 creates the (1) DiscoveryWeb and (2) DiscoveryRO database accounts with null passwords, which could allow attackers to gain privileges or prevent Discovery from running by setting another password."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-11-04T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://securityresponse.symantec.com/avcenter/security/Content/2005.10.24.html"},{"name":"1015097","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015097"},{"name":"112","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/112"},{"name":"15188","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15188"},{"name":"17302","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17302"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-3316","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The installation of ON Symantec Discovery 4.5.x and Symantec Discovery 6.0 creates the (1) DiscoveryWeb and (2) DiscoveryRO database accounts with null passwords, which could allow attackers to gain privileges or prevent Discovery from running by setting another password."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://securityresponse.symantec.com/avcenter/security/Content/2005.10.24.html","refsource":"CONFIRM","url":"http://securityresponse.symantec.com/avcenter/security/Content/2005.10.24.html"},{"name":"1015097","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015097"},{"name":"112","refsource":"SREASON","url":"http://securityreason.com/securityalert/112"},{"name":"15188","refsource":"BID","url":"http://www.securityfocus.com/bid/15188"},{"name":"17302","refsource":"SECUNIA","url":"http://secunia.com/advisories/17302"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-3316","datePublished":"2005-10-27T04:00:00.000Z","dateReserved":"2005-10-27T00:00:00.000Z","dateUpdated":"2024-08-07T23:10:07.588Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-10-27 10:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:discovery:6.0:*:*:*:*:*:*:*","matchCriteriaId":"CE64C169-45AB-4AA1-B4AA-9F9F596DB982"},{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:on_command_discovery:standard_4.5:*:*:*:*:*:*:*","matchCriteriaId":"77BCD94C-FEFF-4337-B198-981973D17083"},{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:on_command_discovery:web_4.5:*:*:*:*:*:*:*","matchCriteriaId":"B022BB94-7256-4E70-A415-4BD83038DCA2"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3316","Ordinal":"1","Title":"CVE-2005-3316","CVE":"CVE-2005-3316","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3316","Ordinal":"1","NoteData":"The installation of ON Symantec Discovery 4.5.x and Symantec Discovery 6.0 creates the (1) DiscoveryWeb and (2) DiscoveryRO database accounts with null passwords, which could allow attackers to gain privileges or prevent Discovery from running by setting another password.","Type":"Description","Title":"CVE-2005-3316"},{"CveYear":"2005","CveId":"3316","Ordinal":"2","NoteData":"2005-10-27","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"3316","Ordinal":"3","NoteData":"2005-11-04","Type":"Other","Title":"Modified"}]}}}