SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-15534

The Norton App Lock prior to version 1.3.0.13 can be susceptible to an authentication bypass exploit.

MEDIUM 6.7EPSS 0.40%

Does this matter?

Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.

Description

The Norton App Lock prior to version 1.3.0.13 can be susceptible to an authentication bypass exploit. In this type of circumstance, the exploit can allow the user to kill the app to prevent it from locking the device, thereby allowing the individual to gain device access.

CVSS 3.0
6.7 MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.40% probability · 34th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
symantec/norton app lock
Source
secure@symantec.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.