ZeroHour

CVE-2016-3648

CVSS 3.0
8.8 high
EPSS
2%p83
Published
()
Modified
Description

Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to bypass the Authentication Lock protection mechanism, and conduct brute-force password-guessing attacks against management-console accounts, by entering data into the authorization window.

Vendors
symantec
Products
endpoint protection manager
Weakness
CWE-200, CWE-254
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.