Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 stores the Application Identity Account password in memory in cleartext, which allows local users to gain privileges and modify clients of the Deployment Solution Server.
Threat-Mapped Scoring
Score: 3.0
Priority: P2 - Serious (High)
S1 – Steal Customer Account Information
EPSS
Score: 0.00043 Percentile:
0.12449
CVSS Scoring
CVSS v3.1 Score: 7.8
Severity: HIGH
Mapped CWE(s)
CWE-312
: Cleartext Storage of Sensitive Information
All CAPEC(s)
CAPEC-37: Retrieve Embedded Sensitive Data
CAPEC(s) with Mapped TTPs
CAPEC-37: Retrieve Embedded Sensitive Data
Mapped TTPs: