First published: Fri Dec 31 2004(Updated: )
AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers to gain administrator access.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Altiris Deployment Solution | =6.1-sp1 | |
Altiris Deployment Solution | =6.1 | |
Altiris Deployment Solution | =5.5 | |
Altiris Deployment Solution | =6.0 | |
Altiris Deployment Solution | =5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2622 is considered a critical vulnerability due to the potential for unauthorized remote access by malicious servers.
To fix CVE-2004-2622, ensure that the configuration of Altiris Deployment Solution requires proper authentication for device connections.
CVE-2004-2622 affects Altiris Deployment Solution versions 5.0.1, 5.5, 6.0, and 6.1.
Attackers can gain administrator access to the system through CVE-2004-2622 without proper authentication.
While CVE-2004-2622 is an older vulnerability, it remains relevant for systems still utilizing the affected versions of Altiris Deployment Solution.