Vulnerability Name: | CVE-2016-5306 (CCN-114609) | ||||||||||||
Assigned: | 2016-06-28 | ||||||||||||
Published: | 2016-06-28 | ||||||||||||
Updated: | 2017-09-01 | ||||||||||||
Summary: | Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for unintended HTTP traffic on port 8445. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) 4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
4.0 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-254 CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-5306 Source: BID Type: UNKNOWN 91449 Source: CCN Type: BID-91449 Symantec Endpoint Protection Manager and Client CVE-2016-5306 Security Bypass Vulnerability Source: SECTRACK Type: UNKNOWN 1036196 Source: XF Type: UNKNOWN symantec-cve20165306-info-disc(114609) Source: CCN Type: Symantec Security Advisory SYM16-011 Symantec Endpoint Protection Manager Multiple Security Issues Source: CONFIRM Type: Vendor Advisory https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160628_01 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |