CVE-2011-3478: Critical severity symantec pcanywhere vulnerability
The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), does not properly filter login and authentication data, which allows remote attackers to execute arbitrary code via a crafted session on TCP port 5631.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3478?
CVE-2011-3478 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2011-3478?
To fix CVE-2011-3478, upgrade to the latest version of Symantec pcAnywhere that addresses this vulnerability.
What are the affected versions of Symantec pcAnywhere for CVE-2011-3478?
CVE-2011-3478 affects Symantec pcAnywhere versions 12.5.x through 12.5.3 and 12.6.x up to version 12.6.7580.
What type of attacks can exploit CVE-2011-3478?
CVE-2011-3478 can be exploited by remote attackers sending crafted login and authentication data.
Is there a workaround for CVE-2011-3478?
While patching is the preferred solution for CVE-2011-3478, temporary measures may include disabling remote access or restricting access to trusted networks.