CVE-2016-3648
high
CVSS v3
8.8
CVSS v2
4.0
VIR risk
8.8
Description
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to bypass the Authentication Lock protection mechanism, and conduct brute-force password-guessing attacks against management-console accounts, by entering data into the authorization window.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secure@symantec.com — https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160628_01
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| symantec | endpoint_protection_manager | {"endIncluding":"12.1.6"} | |
References
- http://www.securityfocus.com/bid/91441
- http://www.securitytracker.com/id/1036196
- https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160628_01
- http://www.securityfocus.com/bid/91441
- http://www.securitytracker.com/id/1036196
- https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160628_01
CWEs
CWE-200 CWE-254
Verify integrity in audit chain (admin only). AS-IS.