Vulnerability Name: | CVE-2013-5014 (CCN-91102) | ||||||||
Assigned: | 2013-07-29 | ||||||||
Published: | 2014-02-13 | ||||||||
Updated: | 2014-03-26 | ||||||||
Summary: | The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protection Center Small Business Edition 12.x before 12.1.4023.4080, allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 6.2 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
6.2 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-5014 Source: CCN Type: SA56798 Symantec Endpoint Protection Manager XML External Entities Vulnerability Source: EXPLOIT-DB Type: UNKNOWN 31853 Source: EXPLOIT-DB Type: UNKNOWN 31917 Source: BID Type: UNKNOWN 65466 Source: CCN Type: BID-65466 Symantec Endpoint Protection Manager CVE-2013-5014 XML External Entity Injection Vulnerability Source: CCN Type: SYM14-004 Symantec Endpoint Protection Manager Vulnerabilities Source: CONFIRM Type: Vendor Advisory http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20140213_00 Source: XF Type: UNKNOWN symantec-endpoint-cve20135014-info-disc(91102) Source: CCN Type: Packet Storm Security [02-23-2014] Symantec Endpoint Protection Manager Remote Command Execution Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [02-23-2014] Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [02-26-2014] Source: MISC Type: UNKNOWN https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20140218-0_Symantec_Endpoint_Protection_Multiple_critical_vulnerabilities_wo_poc_v10.txt | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |