Symantec Endpoint Protection CVE-2011-0551 Cross Site Request Forgery Vulnerability
BID:49101
Info
Symantec Endpoint Protection CVE-2011-0551 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 49101 |
| Class: | Unknown |
| CVE: |
CVE-2011-0551 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 10 2011 12:00AM |
| Updated: | Jan 16 2012 09:30PM |
| Credit: | Sow Ching Shiong through Secunia Labs |
| Vulnerable: |
Symantec Endpoint Protection 11.0 RU6-MP3(11.0.6300) 0 Symantec Endpoint Protection 11.0 RU6-MP2(11.0.6200) 0 Symantec Endpoint Protection 11.0 RU6-MP1(11.0.6100) 0 Symantec Endpoint Protection 12.1 Symantec Endpoint Protection 12.1 Symantec Endpoint Protection 11.0 RU6(11.0.600x) |
| Not Vulnerable: |
Symantec Endpoint Protection 12.1 RU1 Symantec Endpoint Protection 11 RU7 |
Discussion
Symantec Endpoint Protection CVE-2011-0551 Cross Site Request Forgery Vulnerability
Symantec Endpoint Protection is prone to an unspecified cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application. Other attacks are also possible.
The following products are vulnerable:
Symantec Endpoint Protection 11.0 RU6(11.0.600x)
Symantec Endpoint Protection 11.0 RU6-MP1(11.0.6100)
Symantec Endpoint Protection 11.0 RU6-MP2(11.0.6200)
Symantec Endpoint Protection 11.0 RU6-MP3(11.0.6300)
Symantec Endpoint Protection is prone to an unspecified cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application. Other attacks are also possible.
The following products are vulnerable:
Symantec Endpoint Protection 11.0 RU6(11.0.600x)
Symantec Endpoint Protection 11.0 RU6-MP1(11.0.6100)
Symantec Endpoint Protection 11.0 RU6-MP2(11.0.6200)
Symantec Endpoint Protection 11.0 RU6-MP3(11.0.6300)
Exploit / POC
Symantec Endpoint Protection CVE-2011-0551 Cross Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim to open a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim to open a malicious URI.
Solution / Fix
Symantec Endpoint Protection CVE-2011-0551 Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the reference for more details.
Solution:
Updates are available. Please see the reference for more details.
References
Symantec Endpoint Protection CVE-2011-0551 Cross Site Request Forgery Vulnerability
References:
References: