7.5
CVSSv2

CVE-2014-3437

Published: 07/11/2014 Updated: 09/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote malicious users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Vulnerable Product Search on Vulmon Subscribe to Product

symantec endpoint protection manager 12.1.1

symantec endpoint protection manager 12.1.2

symantec endpoint protection manager 12.1.0

symantec endpoint protection manager 12.1.3

symantec endpoint protection manager

Exploits

SEC Consult Vulnerability Lab Security Advisory < 20141106-0 > ======================================================================= title: XXE & XSS & Arbitrary File Write vulnerabilities product: Symantec Endpoint Protection vulnerable version: 12140234080 fixed version: 1215 (RU 5) ...
Symantec Endpoint Protection version 12140234080 suffers from XXE injection, cross site scripting, and arbitrary file write vulnerabilities ...