QID 375671
Date Published: 2021-07-12
QID 375671: Symantec Endpoint Protection Manager (SEPM) Remote Code Execution Vulnerability(SYMSA18255)
Symantec Endpoint Protection, developed by Broadcom Inc., is a security software suite that consists of anti-malware, intrusion prevention and firewall features for server and desktop computers.
CVE-2020-12596 : The vulnerability allows a remote attacker to gain access to potentially sensitive information. The vulnerability exists due to session tokens can be exposed via the URL in a GET request.
Affected Versions:
Symantec Endpoint Protection Manager (SEPM) Prior to 14.3 RU2
QID Detection Logic (Authenticated):
This QID checks for the vulnerable version of Symantec Endpoint Protection Manager (SEPM)
A remote attacker can obtain session token and gain unauthorized access to the application.
Solution
The vendor has released patch. Please visit SYMSA18255 to get the Fixed version Information.
You can download the Symantec Endpoint Protection on Broadcom Download Center and visit here for download instruction.
You can download the Symantec Endpoint Protection on Broadcom Download Center and visit here for download instruction.
Vendor References
CVEs related to QID 375671
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SYMSA18255 |
|