Data Center Security
Vendor:
First CVE: Jan 21, 2015 · Active for 11 years
6
Total CVEs
More Total CVEs than 80% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Data Center Security over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 21, 2015
11 years ago
Most Recent CVE
Apr 6, 2020
2,300 days ago
CVE Severity & Scoring
Data Center Security6 CVEs
17%
33%
50%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (16.7%)
Network0 (0.0%)
Unknown5 (83.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (16.7%)
High0 (0.0%)
Unknown5 (83.3%)
User Interaction
None1 (16.7%)
Unknown5 (83.3%)
Required0 (0.0%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None0 (0.0%)
Unknown5 (83.3%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-9226HIGH The management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows loca | Jan 21, 2015 | 7.2 | 32 | NO | YES |
CVE-2014-7289MEDIUM SQL injection vulnerability in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0 | Jan 21, 2015 | 6.5 | 27 | NO | YES |
CVE-2014-3440HIGH The Agent Control Interface in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0 | Jan 21, 2015 | 9.0 | 25 | NO | NO |
CVE-2014-9225MEDIUM The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x thro | Jan 21, 2015 | 4.0 | 24 | NO | YES |
Cross-site scripting (XSS) vulnerability in the ajaxswing webui in the Management Console server in the management server in Symantec Critical System Protection (SCSP) 5.2.9 throug | Jan 21, 2015 | 3.5 | 21 | NO | YES |
CVE-2020-5832HIGH Symantec Data Center Security Manager Component, prior to 6.8.2 (aka 6.8 MP2), may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attac | Apr 6, 2020 | 7.8 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
66.7% of CVEs· 93rd percentile
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Data Center Security
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.0.0 | 5 | 6.0 | 4.6% | 0 | 4 |