>> Symantec Veritas Storage Foundation Security Bypass Vulnerability
Title : Symantec Veritas Storage Foundation Security Bypass Vulnerability VUPEN ID : VUPEN/ADV-2008-2395 CVE ID : GENERIC-MAP-NOMATCH CWE ID : CWE-287
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-08-18
Technical Description
A vulnerability has been identified in Symantec Veritas Storage Foundation, which could be exploited by remote attackers to bypass security restrictions and compromise a vulnerable system. This issue is caused by an error in the management console that allows NULL NTLMSSP authentication, which could allow a remote attacker to add, modify, or delete snapshots schedules and execute arbitrary code with SYSTEM privileges.