CVE-2017-15528
LOWInstall Norton Security < 7.6 - Certificate Spoofing via Improper Certificate Validation
Title source: llmDescription
Prior to v 7.6, the Install Norton Security (INS) product can be susceptible to a certificate spoofing vulnerability, which is a type of attack whereby a maliciously procured certificate binds the public key of an attacker to the domain name of the target.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/101796
Third Party Advisory x_refsource_misc
https://www.info-sec.ca/advisories/Norton-Security.html
Vendor Advisory x_refsource_confirm
https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20171121_00
Scores
CVSS v3
3.7
EPSS
0.0061
EPSS Percentile
44.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Details
CWE
CWE-295
Status
published
Products (1)
norton/install_norton_security
< 7.6
Published
Nov 22, 2017
Tracked Since
Feb 18, 2026