CVE-2013-5008
Estado: ModificadaMedia (4.6)—
The agent and task-agent components in Symantec Management Platform 7.0 and 7.1 before 7.1 SP2 Mp1.1v7 rollup, as used in certain Altiris products, use the same registry-entry encryption key across different customers' installations, which makes it easier for local users to obtain sensitive information about package-server access, or cause a denial of service, by leveraging knowledge of this key.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 4.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-200
Referencias
- http://www.securityfocus.com/bid/62757
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20131008_00
- http://www.securityfocus.com/bid/62757
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20131008_00
JSON original (NVD)
Mostrar
{
"id": "CVE-2013-5008",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.6,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secure@symantec.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2013-10-10T10:55:06.537",
"references": [
{
"url": "http://www.securityfocus.com/bid/62757",
"source": "secure@symantec.com"
},
{
"url": "http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20131008_00",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "secure@symantec.com"
},
{
"url": "http://www.securityfocus.com/bid/62757",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20131008_00",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The agent and task-agent components in Symantec Management Platform 7.0 and 7.1 before 7.1 SP2 Mp1.1v7 rollup, as used in certain Altiris products, use the same registry-entry encryption key across different customers' installations, which makes it easier for local users to obtain sensitive information about package-server access, or cause a denial of service, by leveraging knowledge of this key."
},
{
"lang": "es",
"value": "Los componentes del agente y del task-agent de Symantec Management Platform 7.0 y 7.1 SP2 Mp1.1v7 rollup, tal como se utiliza en algunos productos de Altiris, utilizan la misma clave de cifrado a través del registro de entrada para instalaciones de diferentes clientes, lo que hace que sea más fácil para los usuarios locales obtener información sensible acerca del acceso de paquetes del servidor, o causar una denegación de servicio, mediante el aprovechamiento de los conocimientos de esta clave."
}
],
"lastModified": "2026-06-16T23:58:14.413",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:symantec:management_platform:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3B04B5F5-B488-4F85-9CEB-739E8B99FC54"
},
{
"criteria": "cpe:2.3:a:symantec:management_platform:7.0:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "03C0AEC5-CB51-455B-A76B-F3F7D60F884A"
},
{
"criteria": "cpe:2.3:a:symantec:management_platform:7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7184C7BB-3001-473F-BBE2-B52542A7A09D"
},
{
"criteria": "cpe:2.3:a:symantec:management_platform:7.1:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4BB7849A-04D6-49F1-B5BD-CBA25714FF92"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secure@symantec.com"
}