Endpoint Protection Manager

Vendor:

First CVE: Jun 20, 2013 · Active for 13 years

41
Total CVEs
More Total CVEs than 98% of tracked products
6.8
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 30% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Endpoint Protection Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 20, 2013
13 years ago
Most Recent CVE
May 11, 2020
2,269 days ago

CVE Severity & Scoring

Endpoint Protection Manager41 CVEs
All CVEs353,173 CVEs
LowMediumHigh
Attack Vector
Local10 (24.4%)
Network15 (36.6%)
Unknown15 (36.6%)
Physical1 (2.4%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (58.5%)
High2 (4.9%)
Unknown15 (36.6%)
User Interaction
None18 (43.9%)
Unknown15 (36.6%)
Required8 (19.5%)
Privileges Required
Low22 (53.7%)
High0 (0.0%)
None4 (9.8%)
Unknown15 (36.6%)

Top CVEs

Signals from CVEs in this product scope (41 CVEs).

41 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protection Center Small Business Editi
Feb 14, 20147.578NOYES
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a crafted password-reset action
Aug 1, 20157.572NOYES
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to write to arbitrary files, and consequently obtai
Aug 1, 20155.557NOYES
SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protect
Feb 14, 20146.556NOYES
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to gain privileges via unspecified vectors.
Aug 1, 20158.552NOYES
Multiple cross-site request forgery (CSRF) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users
Jun 30, 20168.033NOYES
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via X
Nov 7, 20147.532NOYES
Open redirect vulnerability in a report-routing component in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to redirect users to
Jun 30, 20166.830NOYES
Buffer overflow in secars.dll in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1.x before 12.1.3, and Symantec Endpoint Protection Center (SPC) Small Bus
Jun 20, 20137.930NOYES
ConsoleServlet in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to write to arbitrary files via unspecified vectors.
Nov 7, 20146.127NOYES

Exploit Exposure

Signals from CVEs in this product scope (41 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
5 CVEs
12.2% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
12 CVEs
29.3% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (41 CVEs).

Media Mentions

Signals from CVEs in this product scope (41 CVEs).

Top CNAs Publishing CVEs For Endpoint Protection Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
14.273.80.4%00
14.117.81.7%00
14.0.117.81.7%00
1417.81.7%00
12.1.356.422.9%05
12.1.266.619.8%06
12.1.166.619.8%06
12.1.0136.620.2%09
12.117.81.7%00
11.027.048.2%02