VulnerabilityModified
CVE-2018-12237
The Symantec Reporter CLI 10.1 prior to 10.1.5.6 and 10.2 prior to 10.2.1.8 is susceptible to an OS command injection vulnerability.
HIGH 7.2EPSS 2.74%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.74%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Symantec Reporter CLI 10.1 prior to 10.1.5.6 and 10.2 prior to 10.2.1.8 is susceptible to an OS command injection vulnerability. An authenticated malicious administrator with Enable mode access can execute arbitrary OS commands with elevated system privileges.
- CVSS 3.0
- 7.2 HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.74% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- symantec/reporter
- Source
- secure@symantec.com
References
- http://www.securityfocus.com/bid/106518Third Party Advisory, VDB Entry
- https://support.symantec.com/en_US/article.SYMSA1465.htmlVendor Advisory
- http://www.securityfocus.com/bid/106518Third Party Advisory, VDB Entry
- https://support.symantec.com/en_US/article.SYMSA1465.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.