Password Protection Bypass in Symantec Endpoint Protection by Symantec
CVE-2019-12756
2.3LOW
Key Information:
- Vendor
- Symantec
- Vendor
- CVE Published:
- 15 November 2019
Summary
Symantec Endpoint Protection (SEP) versions prior to 14.2 RU2 are exposed to a password protection bypass vulnerability. This security flaw enables individuals with local administrator privileges to circumvent the secondary layer of password protection, potentially allowing unauthorized access to protected features and sensitive configurations.
Affected Version(s)
Symantec Endpoint Protection (SEP) prior to 14.2 RU2
References
CVSS V3.1
Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved