CVE-2000-0324: Medium severity symantec pcanywhere vulnerability
pcAnywhere 8.x and 9.0 allows remote attackers to cause a denial of service via a TCP SYN scan, e.g. by nmap.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Symantec pcAnywherefrom your environment.Uninstall pcAnywhere from systems where it is not required to eliminate exposure to the TCP SYN scan denial-of-service issue.
- Configuration
Stop and disable the pcAnywhere service on affected hosts until a vendor fix or acceptable mitigation is available.
Symantec pcAnywhere service = disabled - Compensating control
Restrict network access to the pcAnywhere service at the perimeter and internal firewalls/ACLs to only trusted management IPs and networks; block unsolicited TCP SYN scans and deny inbound access to pcAnywhere ports from untrusted sources.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0324?
CVE-2000-0324 is classified as a denial of service vulnerability.
How can CVE-2000-0324 be exploited?
CVE-2000-0324 can be exploited by remote attackers using a TCP SYN scan, such as with the nmap tool.
Which versions of pcAnywhere are affected by CVE-2000-0324?
CVE-2000-0324 affects Symantec pcAnywhere versions 8.x and 9.0, including specific versions like 8.0.1, 8.0.2, and 9.2.
What impact does CVE-2000-0324 have on affected systems?
The impact of CVE-2000-0324 includes causing a denial of service that may disrupt normal operations of the pcAnywhere service.
How can I protect against CVE-2000-0324?
To protect against CVE-2000-0324, it is recommended to implement network filtering rules to block unnecessary TCP SYN scans.