CVE-2017-15531
CRITICALSymantec Reporter 9.5-9.5.4.1 and 10.1-10.1.5.5 - Unauthenticated Brute Force Attack via Management Interface
Title source: llmDescription
Symantec Reporter 9.5 prior to 9.5.4.1 and 10.1 prior to 10.1.5.5 does not restrict excessive authentication attempts for management interface users. A remote attacker can use brute force search to guess a user password and gain access to Reporter.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/102751
Vendor Advisory x_refsource_confirm
https://www.symantec.com/security-center/network-protection-security-advisories/SA158
Scores
CVSS v3
9.8
EPSS
0.0281
EPSS Percentile
86.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-287
Status
published
Products (2)
symantec/reporter
10.1
symantec/reporter
9.5 - 9.5.4.1
Published
Jan 23, 2018
Tracked Since
Feb 18, 2026