Vulnerability Description
Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNet SafeDisk 4.1 (0.5643) and earlier use weak permissions (Everyone: Full Control) for a folder under %PROGRAMFILES%\Infotecs, which allows local users to gain privileges via a Trojan horse (1) executable file or (2) DLL file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Infotecs | Vipnet Client | <= 3.2.10 |
| Infotecs | Vipnet Coordinator | <= 3.2.10 |
| Infotecs | Vipnet Personal Firewall | <= 3.1 |
| Infotecs | Vipnet Safedisk | <= 4.1 |
Related Weaknesses (CWE)
References
- http://archives.neohapsis.com/archives/bugtraq/2013-05/0072.html
- http://archives.neohapsis.com/archives/bugtraq/2013-05/0072.html
FAQ
What is CVE-2013-3496?
CVE-2013-3496 is a vulnerability with a CVSS score of 7.2 (HIGH). Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNet SafeDisk 4.1 (0.5643) and earlier use weak permis...
How severe is CVE-2013-3496?
CVE-2013-3496 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-3496?
Check the references section above for vendor advisories and patch information. Affected products include: Infotecs Vipnet Client, Infotecs Vipnet Coordinator, Infotecs Vipnet Personal Firewall, Infotecs Vipnet Safedisk.