CVE-2014-3437

Symantec Endpoint Protection Manager < 12.1 RU5 - XML External Entity Injection via Management Console

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-3437.

AI-analyzed exploit summary This advisory details multiple vulnerabilities in Symantec Endpoint Protection, including XXE, XSS, and arbitrary file write flaws. It provides technical explanations, proof-of-concept examples, and exploitation scenarios, demonstrating a deep understanding of the vulnerabilities.

Description

The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Exploits (1)

exploitdb WRITEUP
webappsjsp
https://www.exploit-db.com/exploits/35181

This advisory details multiple vulnerabilities in Symantec Endpoint Protection, including XXE, XSS, and arbitrary file write flaws. It provides technical explanations, proof-of-concept examples, and exploitation scenarios, demonstrating a deep understanding of the vulnerabilities.

Classification
Writeup 100%
Attack Type
Xss | Ssrf | Dos | Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Symantec Endpoint Protection 12.1.4023.4080
No auth needed
Prerequisites: Ability to perform MitM attacks to impersonate securityresponse.symantec.com · Network access to the target system
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Nov/7
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98525
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/70843
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/533918/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031176

Scores

EPSS 0.0854
EPSS Percentile 94.4%

Details

Status published
Products (5)
symantec/endpoint_protection_manager 12.1.0
symantec/endpoint_protection_manager 12.1.1
symantec/endpoint_protection_manager 12.1.2
symantec/endpoint_protection_manager 12.1.3
symantec/endpoint_protection_manager < 12.1.4
Published Nov 07, 2014
Tracked Since Feb 18, 2026