CVE-2015-1486

Symantec Endpoint Protection Manager <12.1-RU6-MP1 - Auth Bypass

Title source: llm

Description

The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a crafted password-reset action that triggers a new administrative session.

Exploits (2)

metasploit WORKING POC EXCELLENT
by Markus Wulftange, bperry · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/sepm_auth_bypass_rce.rb
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows_x86
https://www.exploit-db.com/exploits/37812

Scores

EPSS 0.7850
EPSS Percentile 99.0%

Classification

CWE
CWE-287
Status draft

Affected Products (1)

symantec/endpoint_protection_manager

Timeline

Published Aug 01, 2015
Tracked Since Feb 18, 2026