Open Redirect Vulnerability in Symantec Endpoint Protection Manager
CVE-2016-5304

6.8MEDIUM

Key Information:

Vendor
Symantec
Vendor
CVE Published:
30 June 2016

Summary

The open redirect vulnerability in Symantec Endpoint Protection Manager allows remote authenticated users to manipulate the report-routing component. This exploitation enables attackers to redirect unsuspecting users to arbitrary and potentially harmful websites, effectively facilitating phishing attacks through various unspecified vectors. Proper security measures and timely updates are essential to mitigate this risk.

References

EPSS Score

8% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.