CVE-2022-25627

MEDIUM

Symantec Identity Manager 14.4 - Authenticated Remote Command Execution via Management Console

Title source: llm
STIX 2.1

Description

An authenticated administrator who has physical access to the environment can carry out Remote Command Execution on Management Console in Symantec Identity Manager 14.4

References (1)

Core 1
Core References

Scores

CVSS v3 6.7
EPSS 0.0018
EPSS Percentile 39.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (2)
broadcom/symantec_identity_governance_and_administration 14.3
broadcom/symantec_identity_governance_and_administration 14.4
Published Dec 16, 2022
Tracked Since Feb 18, 2026