Liveupdate Administrator
Vendor:
First CVE: Mar 28, 2011 · Active for 15 years
5
Total CVEs
More Total CVEs than 79% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Liveupdate Administrator over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 28, 2011
15 years ago
Most Recent CVE
Mar 29, 2014
4,504 days ago
CVE Severity & Scoring
Liveupdate Administrator5 CVEs
60%
40%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown5 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown5 (100.0%)
User Interaction
None0 (0.0%)
Unknown5 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown5 (100.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-0545MEDIUM Cross-site request forgery (CSRF) vulnerability in adduser.do in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to hijack the authentication of administ | Mar 28, 2011 | 6.8 | 34 | NO | YES |
CVE-2011-1524MEDIUM Cross-site scripting (XSS) vulnerability in the management login GUI page in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to inject arbitrary web scri | Mar 28, 2011 | 4.3 | 26 | NO | YES |
CVE-2014-1644HIGH The forgotten-password feature in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote attackers to reset arbitrary pa | Mar 29, 2014 | 7.5 | 25 | NO | NO |
CVE-2012-0304MEDIUM Symantec LiveUpdate Administrator before 2.3.1 uses weak permissions (Everyone: Full Control) for the installation directory, which allows local users to gain privileges via a Troj | Jun 22, 2012 | 6.9 | 21 | NO | NO |
CVE-2014-1645HIGH SQL injection vulnerability in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote attackers to execute arbitrary SQL | Mar 29, 2014 | 7.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
40.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Liveupdate Administrator
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.3.1 | 2 | 7.5 | 2.0% | 0 | 0 |
| 2.3.0 | 2 | 7.5 | 2.0% | 0 | 0 |
| 2.2.2.9 | 4 | 7.2 | 1.8% | 0 | 1 |
| 2.2.2 | 4 | 6.5 | 2.1% | 0 | 1 |
| 2.2.1 | 4 | 6.5 | 2.1% | 0 | 1 |
| 2.1.3 | 4 | 6.5 | 2.1% | 0 | 1 |
| 2.1.2 | 4 | 6.5 | 2.1% | 0 | 1 |
| 2.1.0 | 4 | 6.5 | 2.1% | 0 | 1 |
| 1.5.7.19 | 1 | 6.9 | 0.4% | 0 | 0 |
| 1.5.4 | 1 | 6.9 | 0.4% | 0 | 0 |
| 1.5.3.21 | 1 | 6.9 | 0.4% | 0 | 0 |