CVE-2011-0688

Symantec Antivirus - Authentication Bypass

Title source: rule

Description

Intel Alert Management System (aka AMS or AMS2), as used in Symantec Antivirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Center (SSC) 10.x, and Symantec Quarantine Server 3.5 and 3.6, allows remote attackers to execute arbitrary commands via crafted messages over TCP, as discovered by Junaid Bohio, a different vulnerability than CVE-2010-0110 and CVE-2010-0111. NOTE: some of these details are obtained from third party information.

Scores

EPSS 0.0264
EPSS Percentile 85.5%

Classification

CWE
CWE-287
Status draft

Affected Products (39)

symantec/antivirus
symantec/antivirus
symantec/antivirus
symantec/antivirus
symantec/antivirus
symantec/antivirus
symantec/antivirus
symantec/antivirus
symantec/antivirus
symantec/antivirus
symantec/antivirus
symantec/antivirus
symantec/antivirus
symantec/antivirus
symantec/antivirus
... and 24 more

Timeline

Published Jan 31, 2011
Tracked Since Feb 18, 2026