CVE-2012-0290

Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) do not properly handle the client state after abnormal termination of a remote session, which allows remote attackers to obtain access to the client by leveraging an "open client session."

Published: 2012-02-06 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2012-0290 is rated High Risk (70.1/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 2.69%). Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2012-0290

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-03-13 2.61% 2.69% +0.08%
2 2025-03-30 3.68% 2.61% -1.07%
3 2025-03-29 3.68%

Full EPSS history (8 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2012-0290

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
10.0 2.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
10.0 10.0 [email protected]

Weakness enumeration for CVE-2012-0290

Affected software / configurations for CVE-2012-0290

Vendor Product Version Raw CPE
symantec pcanywhere <= 12.5.3 cpe:2.3:a:symantec:pcanywhere:*:*:*:*:*:*:*:*
symantec pcanywhere 5.0 cpe:2.3:a:symantec:pcanywhere:5.0:*:*:*:*:*:*:*
symantec pcanywhere 8.0 cpe:2.3:a:symantec:pcanywhere:8.0:*:*:*:*:*:*:*
symantec pcanywhere 9.2 cpe:2.3:a:symantec:pcanywhere:9.2:*:*:*:*:*:*:*
symantec pcanywhere 10.5 cpe:2.3:a:symantec:pcanywhere:10.5:*:*:*:*:*:*:*
symantec pcanywhere 11.5 cpe:2.3:a:symantec:pcanywhere:11.5:*:*:*:*:*:*:*
symantec pcanywhere 11.5.1 cpe:2.3:a:symantec:pcanywhere:11.5.1:*:*:*:*:*:*:*
symantec pcanywhere 12.1 cpe:2.3:a:symantec:pcanywhere:12.1:*:*:*:*:*:*:*
symantec pcanywhere 12.5 cpe:2.3:a:symantec:pcanywhere:12.5:sp1:*:*:*:*:*:*
symantec pcanywhere 12.5 cpe:2.3:a:symantec:pcanywhere:12.5:sp2:*:*:*:*:*:*
symantec pcanywhere 12.5 cpe:2.3:a:symantec:pcanywhere:12.5:sp3:*:*:*:*:*:*
symantec pcanywhere 12.5.265 cpe:2.3:a:symantec:pcanywhere:12.5.265:*:*:*:*:*:*:*
symantec pcanywhere 12.5 cpe:2.3:a:symantec:pcanywhere:12.5:*:*:*:*:*:*:*
symantec pcanywhere 12.5.539 cpe:2.3:a:symantec:pcanywhere:12.5.539:*:*:*:*:*:*:*
symantec pcanywhere 12.6.65 cpe:2.3:a:symantec:pcanywhere:12.6.65:*:*:*:*:*:*:*
symantec pcanywhere 12.6.7580 cpe:2.3:a:symantec:pcanywhere:12.6.7580:*:*:*:*:*:*:*
symantec altiris_client_management_suite_pcanywhere_solution 12.5 cpe:2.3:a:symantec:altiris_client_management_suite_pcanywhere_solution:12.5:*:*:*:*:*:*:*
symantec altiris_client_management_suite_pcanywhere_solution 12.5 cpe:2.3:a:symantec:altiris_client_management_suite_pcanywhere_solution:12.5:sp1:*:*:*:*:*:*
symantec altiris_client_management_suite_pcanywhere_solution 12.5 cpe:2.3:a:symantec:altiris_client_management_suite_pcanywhere_solution:12.5:sp2:*:*:*:*:*:*
symantec altiris_client_management_suite_pcanywhere_solution 12.6 cpe:2.3:a:symantec:altiris_client_management_suite_pcanywhere_solution:12.6:*:*:*:*:*:*:*
symantec altiris_client_management_suite_pcanywhere_solution 12.6 cpe:2.3:a:symantec:altiris_client_management_suite_pcanywhere_solution:12.6:sp1:*:*:*:*:*:*
symantec altiris_client_management_suite_pcanywhere_solution 12.6 cpe:2.3:a:symantec:altiris_client_management_suite_pcanywhere_solution:12.6:sp2:*:*:*:*:*:*
symantec altiris_deployment_solution_remote_pcanywhere_solution 12.5 cpe:2.3:a:symantec:altiris_deployment_solution_remote_pcanywhere_solution:12.5:*:*:*:*:*:*:*
symantec altiris_deployment_solution_remote_pcanywhere_solution 12.5 cpe:2.3:a:symantec:altiris_deployment_solution_remote_pcanywhere_solution:12.5:sp1:*:*:*:*:*:*
symantec altiris_deployment_solution_remote_pcanywhere_solution 12.5 cpe:2.3:a:symantec:altiris_deployment_solution_remote_pcanywhere_solution:12.5:sp2:*:*:*:*:*:*
symantec altiris_deployment_solution_remote_pcanywhere_solution 12.6 cpe:2.3:a:symantec:altiris_deployment_solution_remote_pcanywhere_solution:12.6:*:*:*:*:*:*:*
symantec altiris_deployment_solution_remote_pcanywhere_solution 12.6 cpe:2.3:a:symantec:altiris_deployment_solution_remote_pcanywhere_solution:12.6:sp1:*:*:*:*:*:*
symantec altiris_deployment_solution_remote_pcanywhere_solution 12.6 cpe:2.3:a:symantec:altiris_deployment_solution_remote_pcanywhere_solution:12.6:sp2:*:*:*:*:*:*

References for CVE-2012-0290

cvelogic Threat Intelligence