{"api_version":"1","generated_at":"2026-07-23T12:27:05+00:00","cve":"CVE-2008-1754","urls":{"html":"https://cve.report/CVE-2008-1754","api":"https://cve.report/api/cve/CVE-2008-1754.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-1754","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-1754"},"summary":{"title":"CVE-2008-1754","description":"Symantec Altiris Deployment Solution before 6.9.164 stores the Deployment Solution Agent (aka AClient) password in cleartext in memory, which allows local users to obtain sensitive information by dumping the AClient.exe process memory.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-04-11 21:05:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-310","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"1.7","severity":"","vector":"AV:L/AC:L/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:S/C:P/I:N/A:N","baseScore":1.7,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2008/1197/references","name":"http://www.vupen.com/english/advisories/2008/1197/references","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/28707","name":"http://www.securityfocus.com/bid/28707","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Altiris Deployment Solution AClient Password Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/44388","name":"http://www.osvdb.org/44388","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/29771","name":"http://secunia.com/advisories/29771","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Symantec Altiris Deployment Solution AClient Password Disclosure - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41771","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41771","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1019825","name":"http://www.securitytracker.com/id?1019825","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Altiris Deployment Solution Stores AClient Password in Memory in Clear Text - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityresponse.symantec.com/avcenter/security/Content/2008.04.10.html","name":"http://securityresponse.symantec.com/avcenter/security/Content/2008.04.10.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Symantec Security Center","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-1754","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-1754","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"1754","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"altiris_deployment_solution","cpe6":"6.8","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"1754","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"altiris_deployment_solution","cpe6":"6.8.380","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"1754","vulnerable":"1","versionEndIncluding":"6.8","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"altiris_deployment_solution","cpe6":"*","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T08:32:01.308Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"altiris-agent-aclient-info-disclosure(41771)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41771"},{"name":"28707","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/28707"},{"name":"ADV-2008-1197","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/1197/references"},{"name":"29771","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/29771"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://securityresponse.symantec.com/avcenter/security/Content/2008.04.10.html"},{"name":"1019825","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1019825"},{"name":"44388","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/44388"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-04-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Symantec Altiris Deployment Solution before 6.9.164 stores the Deployment Solution Agent (aka AClient) password in cleartext in memory, which allows local users to obtain sensitive information by dumping the AClient.exe process memory."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"altiris-agent-aclient-info-disclosure(41771)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41771"},{"name":"28707","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/28707"},{"name":"ADV-2008-1197","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/1197/references"},{"name":"29771","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/29771"},{"tags":["x_refsource_CONFIRM"],"url":"http://securityresponse.symantec.com/avcenter/security/Content/2008.04.10.html"},{"name":"1019825","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1019825"},{"name":"44388","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/44388"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-1754","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Symantec Altiris Deployment Solution before 6.9.164 stores the Deployment Solution Agent (aka AClient) password in cleartext in memory, which allows local users to obtain sensitive information by dumping the AClient.exe process memory."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"altiris-agent-aclient-info-disclosure(41771)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41771"},{"name":"28707","refsource":"BID","url":"http://www.securityfocus.com/bid/28707"},{"name":"ADV-2008-1197","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/1197/references"},{"name":"29771","refsource":"SECUNIA","url":"http://secunia.com/advisories/29771"},{"name":"http://securityresponse.symantec.com/avcenter/security/Content/2008.04.10.html","refsource":"CONFIRM","url":"http://securityresponse.symantec.com/avcenter/security/Content/2008.04.10.html"},{"name":"1019825","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1019825"},{"name":"44388","refsource":"OSVDB","url":"http://www.osvdb.org/44388"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-1754","datePublished":"2008-04-11T20:28:00.000Z","dateReserved":"2008-04-11T00:00:00.000Z","dateUpdated":"2024-08-07T08:32:01.308Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-04-11 21:05:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-310","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:S/C:P/I:N/A:N","baseScore":1.7,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.1,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:altiris_deployment_solution:*:sp2:*:*:*:*:*:*","versionEndIncluding":"6.8","matchCriteriaId":"2D3DE87D-33E4-4574-AE73-26E93F57EE9C"},{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:altiris_deployment_solution:6.8:sp1:*:*:*:*:*:*","matchCriteriaId":"A1363995-0647-4C83-B3DA-360D5433DCA6"},{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:altiris_deployment_solution:6.8.380:*:*:*:*:*:*:*","matchCriteriaId":"66BB840E-08C0-443A-A4B4-CAAF476AB728"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"1754","Ordinal":"1","Title":"CVE-2008-1754","CVE":"CVE-2008-1754","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"1754","Ordinal":"1","NoteData":"Symantec Altiris Deployment Solution before 6.9.164 stores the Deployment Solution Agent (aka AClient) password in cleartext in memory, which allows local users to obtain sensitive information by dumping the AClient.exe process memory.","Type":"Description","Title":"CVE-2008-1754"},{"CveYear":"2008","CveId":"1754","Ordinal":"2","NoteData":"2008-04-11","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"1754","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}