Symantec_pcAnywhere_Host_Services_Login_Remote_Code_Execution_attack

Strike ID:
G11-5om01
CVSS:
10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
1
Year:
2011

Description

A remote code execution vulnerability has been reported in Symantec pcAnywhere. The vulnerability is caused by improper validating user supplied data during login and authentication with Symantec pcAnywhere host services on port 5631/TCP. By sending crafted messages to the target server, a remote unauthenticated user could possibly execute arbitrary code in the context of the application on the targeted system.

CVE

Bid