CVE-2009-3109

Symantec Altiris Deployment Solution <6.9 SP3 Build 430 - Auth Bypass

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in the AClient agent in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430, when key-based authentication is being used between a deployment server and a client, allows remote attackers to bypass authentication and execute arbitrary commands as SYSTEM by spoofing the deployment server and sending "alternate commands" before the handshake is completed.

References (4)

Core 4
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36502
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/36112
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1022779

Scores

EPSS 0.0038
EPSS Percentile 59.7%

Details

Status published
Products (1)
symantec/altiris_deployment_solution 6.9 (3 CPE variants)
Published Sep 08, 2009
Tracked Since Feb 18, 2026