← Vulnerability feed

Vulnerability record · CVE-2008-6828 · published 8 June 2009

CVE-2008-6828: Symantec altiris deployment solution cleartext storage of sensitive data vulnerability

Symantec · Altiris Deployment Solution

Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 stores the Application Identity Account password in memory in cleartext, which allows local users to gain privileges and modify clients of the Deployment Solution Server.

7.8 CVSS 3.1 High EPSS 0.25% · top 85.5% CWE-312 · Cleartext storage of sensitive data
7.8CVSS 3.1 base score, v2 4.3
0.25%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 stores the Application Identity Account password in memory in cleartext, which allows local users to gain privileges and modify clients of the Deployment Solution Server.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/31773 Broken LinkVendor Advisory
http://securityresponse.symantec.com/avcenter/security/Content/2008.10.20b.html Broken LinkPatchVendor Advisory
http://www.securityfocus.com/bid/31767 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1021072 Broken LinkThird Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2008/2876 Broken LinkPatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/46007 Third Party AdvisoryVDB Entry
http://secunia.com/advisories/31773 Broken LinkVendor Advisory
http://securityresponse.symantec.com/avcenter/security/Content/2008.10.20b.html Broken LinkPatchVendor Advisory
http://www.securityfocus.com/bid/31767 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1021072 Broken LinkThird Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2008/2876 Broken LinkPatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/46007 Third Party AdvisoryVDB Entry

Track CVE-2008-6828 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-3179Symantec altiris deployment solution vulnerabilityMultiple unspecified vulnerabilities in Symantec Altiris Deployment Solution 6.9 might allow remote attackers to execute arbitrary code via unknown c…EPSS 5.3%9.3CVE-2009-3033Symantec altiris deployment solution memory buffer overflow vulnerabilityBuffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in S…EPSS 40%9.3CVE-2009-3031Symantec Altiris ConsoleUtilities ActiveX stack buffer overflowThe BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control (AeXNSConsoleUtilities.dll) contains a stack-based buffer ove…EPSS 45%analysed9.3CVE-2009-3109Symantec altiris deployment solution vulnerabilityUnspecified vulnerability in the AClient agent in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430, when key-based authentication …EPSS 3.8%9.3CVE-2008-4564Autonomy keyview export sdk memory buffer overflow vulnerabilityStack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus Notes, Symantec Mail Security (SMS) produ…EPSS 6.8%7.8CVE-2009-3178Symantec altiris deployment solution vulnerabilityUnspecified vulnerability in mm.exe in Symantec Altiris Deployment Solution 6.9 allows remote attackers to cause a denial of service via unknown atta…EPSS 2.6%7.8CVE-2008-6827Symantec altiris deployment solution missing authentication for critical function vulnerabilityThe ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allows local users to gain SYSTEM…EPSS 1.1%7.5CVE-2008-2286Symantec altiris deployment solution sql injection vulnerabilitySQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows remote attackers to execute…EPSS 33%

Source: NIST National Vulnerability Database (record CVE-2008-6828), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.