CVE-2011-0551
Cross-site request forgery (CSRF) vulnerability in the Web Interface in the Endpoint Protection Manager in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.6300 allows remote attackers to hijack the authentication of administrators for requests…
Does this matter?
Lower severity and a low EPSS score (0.64%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site request forgery (CSRF) vulnerability in the Web Interface in the Endpoint Protection Manager in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.6300 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.64% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- symantec/endpoint protection
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/43662Vendor Advisory
- http://securitytracker.com/id?1025919
- http://www.osvdb.org/74467
- http://www.securityfocus.com/bid/49101
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2011&suid=20110810_00
- http://secunia.com/advisories/43662Vendor Advisory
- http://securitytracker.com/id?1025919
- http://www.osvdb.org/74467
- http://www.securityfocus.com/bid/49101
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2011&suid=20110810_00
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.