CVE-2000-0300: Weak Encryption
The default encryption method of PcAnywhere 9.x uses weak encryption, which allows remote attackers to sniff and decrypt PcAnywhere or NT domain accounts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Symantec pcAnywherefrom your environment.Uninstall pcAnywhere if remote access functionality is not required to eliminate exposure to the weak-default-encryption vulnerability.
- Configuration
Change pcAnywhere's default encryption method in the product configuration to disable the weak default algorithm and enable a stronger encryption option if available.
Symantec pcAnywhere encryption method (default) = disable default weak encryption / use a stronger encryption method - Compensating control
Restrict network exposure of pcAnywhere services using firewall rules, access control lists, or require access via a trusted VPN to prevent remote attackers from sniffing traffic.
- Operational
Rotate PcAnywhere and any affected NT domain account credentials that may have been exposed or decrypted before applying configuration changes or removal.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0300?
The severity of CVE-2000-0300 is considered high due to the use of weak encryption methods.
How do I fix CVE-2000-0300?
To fix CVE-2000-0300, upgrade to a newer version of PcAnywhere that uses stronger encryption methods.
What versions of PcAnywhere are affected by CVE-2000-0300?
CVE-2000-0300 specifically affects Symantec PcAnywhere version 9.0.
What types of attacks can exploit CVE-2000-0300?
CVE-2000-0300 can be exploited by remote attackers to sniff and decrypt account credentials.
Is there a workaround for CVE-2000-0300?
A temporary workaround for CVE-2000-0300 is to avoid using the default encryption method and switch to more secure options if available.