Authentication Bypass Vulnerability in Norton App Lock by Symantec
CVE-2017-15534
6.7MEDIUM
Key Information:
- Vendor
- Symantec Corporation
- Status
- Norton App Lock
- Vendor
- CVE Published:
- 26 March 2018
Summary
The Norton App Lock application, designed to secure mobile devices, has a vulnerability that permits an authentication bypass. Users can exploit this flaw by terminating the app, which disables its locking functionality. Consequently, this allows unauthorized individuals to gain access to the device without proper authentication. It is crucial for users of Norton App Lock to update to version 1.3.0.13 or later to mitigate this risk.
Affected Version(s)
Norton App Lock Prior to version 1.3.0.13
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved