CVE-2017-8391

MEDIUM

CA Client Automation - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

The OS Installation Management component in CA Client Automation r12.9, r14.0, and r14.0 SP1 places an encrypted password into a readable local file during operating system installation, which allows local users to obtain sensitive information by reading this file after operating system installation.

References (3)

Core 3

Scores

CVSS v3 5.5
EPSS 0.0005
EPSS Percentile 14.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-732
Status published
Products (2)
ca/client_automation r12.9
ca/client_automation r14.0 (2 CPE variants)
Published May 06, 2017
Tracked Since Feb 18, 2026