CVE-1999-1323: Medium severity Symantec Norton Antivirus vulnerability
Norton AntiVirus for Internet Email Gateways (NAVIEG) 1.0.1.7 and earlier, and Norton AntiVirus for MS Exchange (NAVMSE) 1.5 and earlier, store the administrator password in cleartext in (1) the navieg.ini file for NAVIEG, and (2) the ModifyPassword registry key in NAVMSE.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Open the navieg.ini file and remove or blank the stored administrator password entry. Reconfigure the gateway to avoid storing the administrator password in cleartext or to use a secure credential storage mechanism.
Norton AntiVirus for Internet Email Gateways (NAVIEG) navieg.ini administrator password = remove / do not store in cleartext - Configuration
Locate the ModifyPassword registry value used by NAVMSE and delete or clear its contents so the administrator password is not stored in cleartext. Reconfigure the product to avoid storing the administrator password in cleartext or to use a secure credential storage mechanism.
Norton AntiVirus for MS Exchange (NAVMSE) ModifyPassword registry value = remove / do not store in cleartext - Compensating control
Restrict filesystem permissions on navieg.ini and restrict registry permissions on the ModifyPassword key to administrators only. Limit network access to management interfaces (firewall/ACLs) and enable monitoring/auditing of access to these files/registry keys until a secure product fix or secure storage method is implemented.
- Operational
Rotate/change the administrator password for affected NAVIEG and NAVMSE instances and any other accounts that used the same password. Search for and remove or secure any backups or copies that may contain the plaintext password.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1323?
CVE-1999-1323 is considered a moderate severity vulnerability due to the exposure of cleartext passwords.
How do I fix CVE-1999-1323?
To fix CVE-1999-1323, update Norton AntiVirus to version 1.0.1.8 or later for NAVIEG and version 1.5.1 or later for NAVMSE.
What systems are affected by CVE-1999-1323?
CVE-1999-1323 affects Norton AntiVirus for Internet Email Gateways versions 1.0.1.7 and earlier, and Norton AntiVirus for MS Exchange versions 1.5 and earlier.
What data is compromised by CVE-1999-1323?
CVE-1999-1323 compromises the administrator password as it is stored in cleartext format.
Is there a workaround for CVE-1999-1323?
A temporary workaround for CVE-1999-1323 is to restrict access to the navieg.ini file and the registry key to prevent unauthorized reading of the passwords.