CVE-2007-3021 describes a critical variable initialization flaw in Symantec Reporting Server versions prior to 1.0.224.0, affecting products like Symantec Client Security and Symantec AntiVirus Corporate Edition. This vulnerability allows unauthenticated attackers to create arbitrary executable files through unspecified manipulations during data export. With a CVSS score of 7.5, it presents a high severity risk due to its network-based attack vector and potential for partial compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.1CPE matchmatch criteria | cpe:2.3:a:symantec:client_security:3.1:*:*:*:*:*:*:* | ||
3.1.394CPE matchmatch criteria | cpe:2.3:a:symantec:client_security:3.1.394:*:*:*:*:*:*:* | ||
3.1.396CPE matchmatch criteria | cpe:2.3:a:symantec:client_security:3.1.396:*:*:*:*:*:*:* | ||
3.1.400CPE matchmatch criteria | cpe:2.3:a:symantec:client_security:3.1.400:*:*:*:*:*:*:* | ||
3.1.401CPE matchmatch criteria | cpe:2.3:a:symantec:client_security:3.1.401:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.