Symantec Corporation Vulnerabilities and Affected Products
Vulnerabilities associated with Norton Security.
Products
Clear product- ProxySG8 vulnerabilities
- Messaging Gateway6 vulnerabilities
- Symantec Endpoint Protection5 vulnerabilities
- Advanced Secure Gateway (ASG)4 vulnerabilities
- Norton App Lock4 vulnerabilities
- ASG3 vulnerabilities
- Symantec Endpoint Encryption3 vulnerabilities
- Endpoint Protection2 vulnerabilities
- Norton Family Android App2 vulnerabilities
- Norton Password Manager2 vulnerabilities
- Norton Security2 vulnerabilities
- Norton; Symantec Endpoint Protection (SEP); Symantec Endpoint Protection Small Business Edition (SEP SBE); Symantec Endpoint Protection Cloud (SEP Cloud)2 vulnerabilities
- Symantec Advanced Secure Gateway (ASG)2 vulnerabilities
- Symantec Encryption Desktop2 vulnerabilities
- Symantec Messaging Gateway2 vulnerabilities
- Symantec ProxySG2 vulnerabilities
- Symantec Reporter2 vulnerabilities
- Blue Coat ASG1 vulnerability
- Blue Coat CAS1 vulnerability
- Content Analysis (CA)1 vulnerability
- Ghost Solution Suite (GSS)1 vulnerability
- Industrial Control System Protection (ICSP)1 vulnerability
- IntelligenceCenter1 vulnerability
- Inventory Plugin for Symantec Management Agent1 vulnerability
- ITMS1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-18366MEDIUM | Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9, and prior to 14.2 RU1, SEP SBE prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22, SEP-12.1.7484.7002 and SEP Cloud prior to 22.16.3 may be susceptible to a kernel memory disclosure, which is a type of issue where a specially crafted IRP request can cause the driver to return uninitialized memory. CWE-908Apr 25, 2019 | CVSS6.5v3.0 | EPSS0.386% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-18369HIGH | Norton Security (Windows client) prior to 22.16.3 and SEP SBE (Windows client) prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22 & SEP-12.1.7484.7002, may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. CWE-426Apr 25, 2019 | CVSS7.8v3.0 | EPSS2.38% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |