CVE-2015-1486
Symantec Endpoint Protection Manager <12.1-RU6-MP1 - Auth Bypass
Title source: llmDescription
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a crafted password-reset action that triggers a new administrative session.
Exploits (2)
metasploit
WORKING POC
EXCELLENT
by Markus Wulftange, bperry · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/sepm_auth_bypass_rce.rb
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows_x86
https://www.exploit-db.com/exploits/37812
References (4)
Scores
EPSS
0.7850
EPSS Percentile
99.0%
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
symantec/endpoint_protection_manager
Timeline
Published
Aug 01, 2015
Tracked Since
Feb 18, 2026