Denial of Service Vulnerability in Symantec Encryption Desktop
CVE-2017-6330

6.5MEDIUM

Key Information:

Vendor
Symantec Corporation
Status
Symantec Encryption Desktop
Vendor
CVE Published:
13 September 2017

Summary

A vulnerability in Symantec Encryption Desktop allows remote attackers to exploit the software by sending specially crafted web requests. This can result in a denial of service through excessive resource consumption, potentially impacting the performance and availability of the product. Users are advised to upgrade to version 10.4.1MP2 or later to mitigate this risk.

Affected Version(s)

Symantec Encryption Desktop SED prior to 10.4.1MP2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.