CVE-2014-1644: High severity Symantec LiveUpdate Administrator vulnerability
The forgotten-password feature in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote attackers to reset arbitrary passwords by providing the e-mail address associated with a user account.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Symantec LiveUpdate Administrator (LUA)to a version that resolves this vulnerability.Fixed in 2.3.2.110
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1644?
CVE-2014-1644 has a medium severity rating due to its potential impact on user account security.
How do I fix CVE-2014-1644?
To fix CVE-2014-1644, upgrade Symantec LiveUpdate Administrator to version 2.3.2 or later.
What systems are impacted by CVE-2014-1644?
CVE-2014-1644 affects Symantec LiveUpdate Administrator versions 2.x prior to 2.3.2.
What types of attacks can exploit CVE-2014-1644?
Attackers can exploit CVE-2014-1644 to reset arbitrary user passwords through the forgotten-password feature.
Is there any workaround for CVE-2014-1644?
Currently, there are no known effective workarounds for CVE-2014-1644 other than upgrading to the patched version.