Vulnerability CVE-2014-3437


Published: 2014-11-07

Description:
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

See advisories in our WLB2 database:
Topic
Author
Date
High
Symantec Endpoint Protection 12.1.4023.4080 XXE / XSS / Arbitrary File Write
Stefan
07.11.2014

Type:

CWE-Other

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Symantec -> Endpoint protection manager 

 References:
http://seclists.org/fulldisclosure/2014/Nov/7
http://www.securityfocus.com/archive/1/533918/100/0/threaded
http://www.securityfocus.com/bid/70843
http://www.securitytracker.com/id/1031176
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20141105_00
https://exchange.xforce.ibmcloud.com/vulnerabilities/98525

Copyright 2024, cxsecurity.com

 

Back to Top