Remote Account Enumeration in Symantec Endpoint Protection Manager
CVE-2016-3649
4.3MEDIUM
Summary
The Symantec Endpoint Protection Manager (SEPM) 12.1 prior to RU6 MP5 allows remote authenticated administrators to exploit a flaw that enables them to enumerate existing administrator accounts through manipulated GET requests. This vulnerability can lead to the exposure of sensitive user information and potentially further attacks within the system.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved