Unauthorized Access Issue in Symantec Industrial Control System Protection
CVE-2019-18380

6.5MEDIUM

What is CVE-2019-18380?

The Symantec Industrial Control System Protection (ICSP) software, specifically version 6.x.x, is subject to a vulnerability that enables unauthorized access, allowing threat actors to potentially create or modify application user accounts without undergoing the necessary authentication process. This could lead to significant security risks within operational technology environments relying on this software, as it may compromise user integrity and facilitate other malicious activities.

Affected Version(s)

Industrial Control System Protection (ICSP) 6.x.x

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-18380 : Unauthorized Access Issue in Symantec Industrial Control System Protection