CVE-2016-5306

MEDIUM

Symantec Endpoint Protection Manager < 12.1.6 - Exposure of Sensitive Information via Missing HSTS Enforcement

Title source: llm
STIX 2.1

Description

Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for unintended HTTP traffic on port 8445.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036196
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/91449

Scores

CVSS v3 5.3
EPSS 0.0034
EPSS Percentile 56.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200 CWE-254
Status published
Products (1)
symantec/endpoint_protection_manager < 12.1.6
Published Jun 30, 2016
Tracked Since Feb 18, 2026