SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-5306

Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for unintended HTTP traffic on…

MEDIUM 5.3EPSS 2.08%

Does this matter?

Lower severity and a low EPSS score (2.08%). Track it; it rarely justifies an emergency change on its own.

Description

Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for unintended HTTP traffic on port 8445.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
2.08% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-200, CWE-254
Affected
symantec/endpoint protection manager
Source
secure@symantec.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.