Denial of Service Vulnerability in Symantec Encryption Desktop
CVE-2017-6330
6.5MEDIUM
Key Information:
- Vendor
- Symantec Corporation
- Status
- Symantec Encryption Desktop
- Vendor
- CVE Published:
- 13 September 2017
Summary
A vulnerability in Symantec Encryption Desktop allows remote attackers to exploit the software by sending specially crafted web requests. This can result in a denial of service through excessive resource consumption, potentially impacting the performance and availability of the product. Users are advised to upgrade to version 10.4.1MP2 or later to mitigate this risk.
Affected Version(s)
Symantec Encryption Desktop SED prior to 10.4.1MP2
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved