CVE-2014-3438

Symantec Endpoint Protection Manager < 12.1 RU5 - Cross-Site Scripting

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-3438.

AI-analyzed exploit summary The document provides a detailed technical analysis of multiple vulnerabilities in Symantec Endpoint Protection, including XXE, XSS, and arbitrary file write/overwrite flaws. It includes proof-of-concept examples and exploitation scenarios, demonstrating a deep understanding of the vulnerabilities.

Description

Multiple cross-site scripting (XSS) vulnerabilities in console interface scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Exploits (1)

exploitdb WRITEUP
webappsjsp
https://www.exploit-db.com/exploits/35181

The document provides a detailed technical analysis of multiple vulnerabilities in Symantec Endpoint Protection, including XXE, XSS, and arbitrary file write/overwrite flaws. It includes proof-of-concept examples and exploitation scenarios, demonstrating a deep understanding of the vulnerabilities.

Classification
Writeup 100%
Attack Type
Xss | Ssrf | Dos | Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Symantec Endpoint Protection 12.1.4023.4080
No auth needed
Prerequisites: Ability to perform MitM attacks · Access to the target network
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98526
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Nov/7
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/70844
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/533918/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031176

Scores

EPSS 0.0392
EPSS Percentile 89.0%

Details

CWE
CWE-79
Status published
Products (5)
symantec/endpoint_protection_manager 12.1.0
symantec/endpoint_protection_manager 12.1.1
symantec/endpoint_protection_manager 12.1.2
symantec/endpoint_protection_manager 12.1.3
symantec/endpoint_protection_manager < 12.1.4
Published Nov 07, 2014
Tracked Since Feb 18, 2026