CVE-2014-3439

Symantec Endpoint Protection Manager <12.1 - RCE

Title source: llm
STIX 2.1

Description

ConsoleServlet in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to write to arbitrary files via unspecified vectors.

Exploits (1)

exploitdb WORKING POC
by SEC Consult · textwebappsjsp
https://www.exploit-db.com/exploits/35181

References (6)

Core 6
Core References
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Nov/7
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/70845
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98527
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/533918/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031176

Scores

EPSS 0.0986
EPSS Percentile 93.0%

Details

Status published
Products (5)
symantec/endpoint_protection_manager 12.1.0
symantec/endpoint_protection_manager 12.1.1
symantec/endpoint_protection_manager 12.1.2
symantec/endpoint_protection_manager 12.1.3
symantec/endpoint_protection_manager < 12.1.4
Published Nov 07, 2014
Tracked Since Feb 18, 2026