PT-2016-4029 · Symantec · Symantec Embedded Security: Critical System Protection+2

Publicado

2016-06-08

·

Atualizado

2021-09-09

·

CVE-2015-8799

CVSS v2.0

7.1

Alta

VetorAV:N/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Symantec Embedded Security: Critical System Protection (SES:CSP) versions 1.0.x through 1.0 before MP5 Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) version 6.5.0 before MP1 Critical System Protection (SCSP) versions prior to 5.2.9 MP6 Data Center Security: Server Advanced Server (DCS:SA) versions 6.x through 6.4 and 6.6 before MP1 Data Center Security: Server Advanced Server and Agents (DCS:SA) versions prior to 6.6 MP1
Description A directory traversal issue in the Management Server allows remote authenticated users to write update-package data to arbitrary agent locations.
Recommendations For Symantec Embedded Security: Critical System Protection (SES:CSP) versions 1.0.x through 1.0 before MP5, update to version 1.0 MP5 or later. For Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) version 6.5.0 before MP1, update to version 6.5.0 MP1 or later. For Critical System Protection (SCSP) versions prior to 5.2.9 MP6, update to version 5.2.9 MP6 or later. For Data Center Security: Server Advanced Server (DCS:SA) versions 6.x through 6.4 and 6.6 before MP1, update to version 6.5 MP1 or later for 6.x and version 6.6 MP1 or later for 6.6. For Data Center Security: Server Advanced Server and Agents (DCS:SA) versions prior to 6.6 MP1, update to version 6.6 MP1 or later.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-8799

Produtos afetados

Critical System Protection
Data Center Security: Server Advanced Server
Symantec Embedded Security: Critical System Protection