CVE-2017-15531

CRITICAL

Symantec Reporter 9.5-9.5.4.1 and 10.1-10.1.5.5 - Unauthenticated Brute Force Attack via Management Interface

Title source: llm
STIX 2.1

Description

Symantec Reporter 9.5 prior to 9.5.4.1 and 10.1 prior to 10.1.5.5 does not restrict excessive authentication attempts for management interface users. A remote attacker can use brute force search to guess a user password and gain access to Reporter.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/102751

Scores

CVSS v3 9.8
EPSS 0.0281
EPSS Percentile 86.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (2)
symantec/reporter 10.1
symantec/reporter 9.5 - 9.5.4.1
Published Jan 23, 2018
Tracked Since Feb 18, 2026