CVE-2017-6323 is a critical XML External Entity (XXE) vulnerability affecting Symantec Management Console versions prior to ITMS 8.1 RU1, 8.0_POST_HF6, and 7.6_POST_HF7. This high-severity vulnerability (CVSS 8.0) allows an authenticated attacker on the local network to exploit a weakly configured XML parser, leading to potential confidential data disclosure, denial of service, server-side request forgery, or port scanning. While no public exploits or active exploitation have been observed, and community discussion is minimal, the potential impact warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.1CPE matchmatch criteria | cpe:2.3:a:symantec:management_console:*:*:*:*:*:*:*:* | ||
7.6CPE matchmatch criteria | cpe:2.3:a:symantec:management_console:7.6:hf7:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:symantec:management_console:8.0:hf6:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.