HIGH · 7.2

CVE-2013-3496

Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNet SafeDisk 4.1 (0.5643) and earlier use weak permis...

Vulnerability Description

Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNet SafeDisk 4.1 (0.5643) and earlier use weak permissions (Everyone: Full Control) for a folder under %PROGRAMFILES%\Infotecs, which allows local users to gain privileges via a Trojan horse (1) executable file or (2) DLL file.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
InfotecsVipnet Client<= 3.2.10
InfotecsVipnet Coordinator<= 3.2.10
InfotecsVipnet Personal Firewall<= 3.1
InfotecsVipnet Safedisk<= 4.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-3496?

CVE-2013-3496 is a vulnerability with a CVSS score of 7.2 (HIGH). Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNet SafeDisk 4.1 (0.5643) and earlier use weak permis...

How severe is CVE-2013-3496?

CVE-2013-3496 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-3496?

Check the references section above for vendor advisories and patch information. Affected products include: Infotecs Vipnet Client, Infotecs Vipnet Coordinator, Infotecs Vipnet Personal Firewall, Infotecs Vipnet Safedisk.