CVE-2008-2291: High severity symantec deployment solution vulnerability
axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 generates credentials with a fixed salt or without any salt, which makes it easier for remote attackers to guess encrypted domain credentials.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2291?
CVE-2008-2291 is classified as a high-severity vulnerability due to the potential for attackers to easily guess encrypted domain credentials.
How do I fix CVE-2008-2291?
To mitigate CVE-2008-2291, upgrade to a patched version of Symantec Altiris Deployment Solution, specifically 6.9.176 or later.
What software versions are affected by CVE-2008-2291?
CVE-2008-2291 affects Symantec Altiris Deployment Solution versions 6.8.x and 6.9.x before 6.9.176.
What type of attack can exploit CVE-2008-2291?
CVE-2008-2291 can be exploited by remote attackers aiming to guess or crack encrypted domain credentials.
Is a workaround available for CVE-2008-2291?
There are no known effective workarounds for CVE-2008-2291; upgrading to a fixed version is the recommended solution.