{"api_version":"1","generated_at":"2026-07-23T10:19:15+00:00","cve":"CVE-2015-8801","urls":{"html":"https://cve.report/CVE-2015-8801","api":"https://cve.report/api/cve/CVE-2015-8801.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-8801","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-8801"},"summary":{"title":"CVE-2015-8801","description":"Race condition in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6 MP5 allows local users to bypass intended restrictions on USB file transfer by conducting filesystem operations before the SEP device manager recognizes a new USB device.","state":"PUBLISHED","assigner":"symantec","published_at":"2016-06-30 23:59:00","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-254","CWE-284","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"2.9","severity":"LOW","vector":"CVSS:3.0/AV:P/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:P/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":2.9,"baseSeverity":"LOW","attackVector":"PHYSICAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.3","severity":"","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:P/A:N","baseScore":3.3,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securitytracker.com/id/1036196","name":"http://www.securitytracker.com/id/1036196","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Endpoint Protection Multiple Bugs Let Remote Users Conduct Cross-Site Scripting, Cross-Site Request Forgery, Server-Side Request Forgery, Security Bypass, File Disclosure, and Open Redirect Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/91446","name":"http://www.securityfocus.com/bid/91446","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Endpoint Protection Manager and Client Local Race Condition Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160628_01","name":"https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160628_01","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisories Relating to Symantec Products - Symantec Endpoint Protection Multiple Security Issues - 2016-06-28T03:00:00 PDT\n\t| Symantec","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-8801","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-8801","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"8801","vulnerable":"1","versionEndIncluding":"12.1.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"endpoint_protection_manager","cpe6":"*","cpe7":"mp4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T08:29:22.069Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160628_01"},{"name":"1036196","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1036196"},{"name":"91446","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/91446"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2016-06-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Race condition in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6 MP5 allows local users to bypass intended restrictions on USB file transfer by conducting filesystem operations before the SEP device manager recognizes a new USB device."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-31T09:57:01.000Z","orgId":"80d3bcb6-88de-48c2-a47e-aebf795f19b5","shortName":"symantec"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160628_01"},{"name":"1036196","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1036196"},{"name":"91446","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/91446"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secure@symantec.com","ID":"CVE-2015-8801","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Race condition in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6 MP5 allows local users to bypass intended restrictions on USB file transfer by conducting filesystem operations before the SEP device manager recognizes a new USB device."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160628_01","refsource":"CONFIRM","url":"https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160628_01"},{"name":"1036196","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1036196"},{"name":"91446","refsource":"BID","url":"http://www.securityfocus.com/bid/91446"}]}}}},"cveMetadata":{"assignerOrgId":"80d3bcb6-88de-48c2-a47e-aebf795f19b5","assignerShortName":"symantec","cveId":"CVE-2015-8801","datePublished":"2016-06-30T23:00:00.000Z","dateReserved":"2016-02-02T00:00:00.000Z","dateUpdated":"2024-08-06T08:29:22.069Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2016-06-30 23:59:00","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-254","CWE-284","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:P/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":2.9,"baseSeverity":"LOW","attackVector":"PHYSICAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":0.4,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:P/A:N","baseScore":3.3,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.4,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:endpoint_protection_manager:*:mp4:*:*:*:*:*:*","versionEndIncluding":"12.1.6","matchCriteriaId":"DCE7769D-5CED-4365-93F3-0D4320470943"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"8801","Ordinal":"1","Title":"CVE-2015-8801","CVE":"CVE-2015-8801","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"8801","Ordinal":"1","NoteData":"Race condition in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6 MP5 allows local users to bypass intended restrictions on USB file transfer by conducting filesystem operations before the SEP device manager recognizes a new USB device.","Type":"Description","Title":"CVE-2015-8801"},{"CveYear":"2015","CveId":"8801","Ordinal":"2","NoteData":"2016-06-30","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"8801","Ordinal":"3","NoteData":"2017-08-31","Type":"Other","Title":"Modified"}]}}}