J-Security Center

Title: Symantec Altiris Deployment Solution Domain Credential Unauthorized Access Vulnerability

Severity: MODERATE

Description:

Symantec Altiris Deployment Solution is software for deploying and managing servers, desktops, notebooks, thin clients, and handheld devices from a centralized location. It is available for Microsoft Windows.

Symantec Altiris Deployment Solution is prone to a vulnerability that allows unauthorized users to gain access to the affected application. This issue occurs within the 'axengine.exe' service, which listens on TCP port 402. The application allows attackers to gain access to domain credentials without proper authorization.

In addition, the encryption algorithm has a weakness. It lacks a salt, allowing the attacker to decrypt the domain credentials.

The attacker can exploit this issue to gain unauthorized access to the affected application.

Affected Products:

  • HP ProLiant Essentials Rapid Deployment Pack (RDP)
  • Symantec Altiris Deployment Solution 6.8
  • Symantec Altiris Deployment Solution 6.8 SP1
  • Symantec Altiris Deployment Solution 6.8 SP2
  • Symantec Altiris Deployment Solution 6.8.380.0
  • Symantec Altiris Deployment Solution 6.9
  • Symantec Altiris Deployment Solution 6.9.164

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.