CVE-2018-12237

HIGH

Symantec Reporter CLI <10.1.5.6, <10.2.1.8 - Command Injection

Title source: llm
STIX 2.1

Description

The Symantec Reporter CLI 10.1 prior to 10.1.5.6 and 10.2 prior to 10.2.1.8 is susceptible to an OS command injection vulnerability. An authenticated malicious administrator with Enable mode access can execute arbitrary OS commands with elevated system privileges.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://support.symantec.com/en_US/article.SYMSA1465.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106518

Scores

CVSS v3 7.2
EPSS 0.0244
EPSS Percentile 85.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
symantec/reporter 10.1 - 10.1.5.6
Published Jan 24, 2019
Tracked Since Feb 18, 2026