« Volver al listado

CVE-2013-4677

Estado: ModificadaMedia (4.3)—

Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 uses weak permissions (Everyone: Read and Everyone: Change) for backup data files, which allows local users to obtain sensitive information or modify the outcome of a restore via direct access to these files.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-4677",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.1,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secure@symantec.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-08-05T13:22:52.693",
  "references": [
    {
      "url": "http://osvdb.org/95939",
      "source": "secure@symantec.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/61487",
      "source": "secure@symantec.com"
    },
    {
      "url": "http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130801_00",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@symantec.com"
    },
    {
      "url": "http://osvdb.org/95939",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/61487",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130801_00",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 uses weak permissions (Everyone: Read and Everyone: Change) for backup data files, which allows local users to obtain sensitive information or modify the outcome of a restore via direct access to these files."
    },
    {
      "lang": "es",
      "value": "Symantec Backup Exec v2010 R3 anterior a v2010 R3 SP3 y v2012 anterior a SP2 utiliza permisos débiles (todos los usuarios: Lectura y todos los usuarios: Cambiar) para archivos de datos de copia de seguridad, lo que permite a usuarios locales obtener información sensible o modificar el resultado de una restauración a través del acceso directo a estos ficheros."
    }
  ],
  "lastModified": "2026-06-16T23:57:42.317",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:symantec:backup_exec:2010:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "006EB76F-8F6B-4D19-81AB-B9133CBC1F47"
            },
            {
              "criteria": "cpe:2.3:a:symantec:backup_exec:2010_r3:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD144D8C-99FA-44DC-949D-DF938AC3C6E8"
            },
            {
              "criteria": "cpe:2.3:a:symantec:backup_exec:2010_r3:sp2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ADFAEEFA-E438-4611-A42E-A70C8F4D3F68"
            },
            {
              "criteria": "cpe:2.3:a:symantec:backup_exec:2012:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "632557AF-509E-4FF8-B0CC-A44ABC56645B"
            },
            {
              "criteria": "cpe:2.3:a:symantec:backup_exec:2012:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DBDF5A56-FE35-49C8-A94B-FE120D2B714B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@symantec.com"
}