Vulnerability Name: | CCN-94760 | ||||||
Published: | 2014-07-22 | ||||||
Updated: | 2014-07-22 | ||||||
Summary: | Symantec Endpoint Protection Manager is vulnerable to a brute force attack, caused by the failure to restrict failed login attempts by the login form. An attacker could exploit this vulnerability to gain access to the system using brute force techniques. | ||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||
CVSS v2 Severity: | 4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
| ||||||
Vulnerability Consequences: | Gain Access | ||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue Jul 22 2014 - 06:39:47 CDT Web Login Bruteforce in Symantec Endpoint Protection Manager Source: CCN Type: BID-68845 Symantec Endpoint Protection Manager Brute Force Authentication Bypass Vulnerability Source: CCN Type: Symantec Web site Endpoint Protection Manager Source: XF Type: UNKNOWN symantec-endpoint-brute-force(94760) Source: CCN Type: Packet Storm Security [07-22-2014] Symantec Endpoint Protection Manager 12.1.4023.4080 Login Bruteforce | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |