6.1
CVSSv2

CVE-2014-3439

Published: 07/11/2014 Updated: 09/10/2018
CVSS v2 Base Score: 6.1 | Impact Score: 6.9 | Exploitability Score: 6.5
VMScore: 615
Vector: AV:A/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

ConsoleServlet in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote malicious users to write to arbitrary files via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

symantec endpoint protection manager 12.1.0

symantec endpoint protection manager 12.1.3

symantec endpoint protection manager

symantec endpoint protection manager 12.1.1

symantec endpoint protection manager 12.1.2

Exploits

SEC Consult Vulnerability Lab Security Advisory < 20141106-0 > ======================================================================= title: XXE & XSS & Arbitrary File Write vulnerabilities product: Symantec Endpoint Protection vulnerable version: 12140234080 fixed version: 1215 (RU 5) ...
Symantec Endpoint Protection version 12140234080 suffers from XXE injection, cross site scripting, and arbitrary file write vulnerabilities ...