CVE-2013-3496

Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNet SafeDisk 4.1 (0.5643) and earlier use weak permissions (Everyone: Full Control) for a folder under %PROGRAMFILES%\Infotecs, which allows local users to gain privileges via a Trojan horse (1) executable file or (2) DLL file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:infotecs:vipnet_client:*:*:*:*:*:*:*:*
cpe:2.3:a:infotecs:vipnet_coordinator:*:*:*:*:*:*:*:*
cpe:2.3:a:infotecs:vipnet_personal_firewall:*:*:*:*:*:*:*:*
cpe:2.3:a:infotecs:vipnet_safedisk:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2013-05-22 13:29

Updated : 2023-12-10 11:16


NVD link : CVE-2013-3496

Mitre link : CVE-2013-3496

CVE.ORG link : CVE-2013-3496


JSON object : View

Products Affected

infotecs

  • vipnet_personal_firewall
  • vipnet_safedisk
  • vipnet_coordinator
  • vipnet_client
CWE
CWE-264

Permissions, Privileges, and Access Controls