Password Protection Bypass in Symantec Endpoint Protection by Symantec
CVE-2019-12756

2.3LOW

Key Information:

Vendor
Symantec
Vendor
CVE Published:
15 November 2019

Summary

Symantec Endpoint Protection (SEP) versions prior to 14.2 RU2 are exposed to a password protection bypass vulnerability. This security flaw enables individuals with local administrator privileges to circumvent the secondary layer of password protection, potentially allowing unauthorized access to protected features and sensitive configurations.

Affected Version(s)

Symantec Endpoint Protection (SEP) prior to 14.2 RU2

References

CVSS V3.1

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.