CVE-2013-4677

Symantec Backup Exec <2010 R3 SP3 & 2012 SP2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 uses weak permissions (Everyone: Read and Everyone: Change) for backup data files, which allows local users to obtain sensitive information or modify the outcome of a restore via direct access to these files.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/95939
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/61487

Scores

EPSS 0.0005
EPSS Percentile 16.3%

Details

CWE
CWE-264
Status published
Products (3)
symantec/backup_exec 2010
symantec/backup_exec 2010_r3 sp1 (2 CPE variants)
symantec/backup_exec 2012 (2 CPE variants)
Published Aug 05, 2013
Tracked Since Feb 18, 2026