ZeroHour

CVE-2016-5306

CVSS 3.0
5.3 medium
EPSS
2%p80
Published
()
Modified
Description

Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for unintended HTTP traffic on port 8445.

Vendors
symantec
Products
endpoint protection manager
Weakness
CWE-200, CWE-254
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.