CVE-2000-0273: Medium severity symantec pcanywhere vulnerability
PCAnywhere allows remote attackers to cause a denial of service by terminating the connection before PCAnywhere provides a login prompt.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Symantec pcAnywherefrom your environment.Uninstall pcAnywhere from systems where it is not required to eliminate the vulnerability exposure.
- Configuration
Disable or stop the pcAnywhere service until a vendor fix or acceptable mitigation is available to prevent remote attackers from causing a denial of service.
Symantec pcAnywhere service_enabled = false - Compensating control
Restrict network access to pcAnywhere to trusted management networks only — block incoming connections to the pcAnywhere service at the perimeter firewall and require VPN access for remote administration.
- Operational
If hosts have been impacted, isolate affected systems for investigation before restoring service; monitor logs for repeated connection-termination attempts and block offending IPs until mitigations are in place.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0273?
CVE-2000-0273 has a moderate severity level as it can cause denial of service in the affected software.
How do I fix CVE-2000-0273?
To mitigate CVE-2000-0273, ensure that you are using the latest version of PCAnywhere and apply any available security patches.
Which versions of PCAnywhere are affected by CVE-2000-0273?
CVE-2000-0273 affects PCAnywhere versions 8.0 and 9.0.
What type of attack does CVE-2000-0273 describe?
CVE-2000-0273 describes a denial of service attack that occurs when a remote attacker terminates the connection before a login prompt is displayed.
Who is the vendor for the affected software in CVE-2000-0273?
The vendor for the affected software in CVE-2000-0273 is Symantec.