{"api_version":"1","generated_at":"2026-07-23T07:54:34+00:00","cve":"CVE-2016-5306","urls":{"html":"https://cve.report/CVE-2016-5306","api":"https://cve.report/api/cve/CVE-2016-5306.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-5306","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-5306"},"summary":{"title":"CVE-2016-5306","description":"Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for unintended HTTP traffic on port 8445.","state":"PUBLISHED","assigner":"symantec","published_at":"2016-06-30 23:59:17","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-200","CWE-254","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securitytracker.com/id/1036196","name":"http://www.securitytracker.com/id/1036196","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Endpoint Protection Multiple Bugs Let Remote Users Conduct Cross-Site Scripting, Cross-Site Request Forgery, Server-Side Request Forgery, Security Bypass, File Disclosure, and Open Redirect Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/91449","name":"http://www.securityfocus.com/bid/91449","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Endpoint Protection Manager and Client CVE-2016-5306 Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160628_01","name":"https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160628_01","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisories Relating to Symantec Products - Symantec Endpoint Protection Multiple Security Issues - 2016-06-28T03:00:00 PDT\n\t| Symantec","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-5306","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-5306","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"5306","vulnerable":"1","versionEndIncluding":"12.1.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"endpoint_protection_manager","cpe6":"*","cpe7":"mp4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T01:00:57.785Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160628_01"},{"name":"1036196","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1036196"},{"name":"91449","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/91449"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2016-06-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for unintended HTTP traffic on port 8445."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-31T09:57:01.000Z","orgId":"80d3bcb6-88de-48c2-a47e-aebf795f19b5","shortName":"symantec"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160628_01"},{"name":"1036196","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1036196"},{"name":"91449","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/91449"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secure@symantec.com","ID":"CVE-2016-5306","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for unintended HTTP traffic on port 8445."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160628_01","refsource":"CONFIRM","url":"https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160628_01"},{"name":"1036196","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1036196"},{"name":"91449","refsource":"BID","url":"http://www.securityfocus.com/bid/91449"}]}}}},"cveMetadata":{"assignerOrgId":"80d3bcb6-88de-48c2-a47e-aebf795f19b5","assignerShortName":"symantec","cveId":"CVE-2016-5306","datePublished":"2016-06-30T23:00:00.000Z","dateReserved":"2016-06-06T00:00:00.000Z","dateUpdated":"2024-08-06T01:00:57.785Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2016-06-30 23:59:17","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-200","CWE-254","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:endpoint_protection_manager:*:mp4:*:*:*:*:*:*","versionEndIncluding":"12.1.6","matchCriteriaId":"DCE7769D-5CED-4365-93F3-0D4320470943"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"5306","Ordinal":"1","Title":"CVE-2016-5306","CVE":"CVE-2016-5306","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"5306","Ordinal":"1","NoteData":"Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for unintended HTTP traffic on port 8445.","Type":"Description","Title":"CVE-2016-5306"},{"CveYear":"2016","CveId":"5306","Ordinal":"2","NoteData":"2016-06-30","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"5306","Ordinal":"3","NoteData":"2017-08-31","Type":"Other","Title":"Modified"}]}}}