PT-2015-3723 · Symantec · Symantec Data Center Security: Server Advanced+1
Published
2015-01-21
·
Updated
2021-08-04
·
CVE-2014-3440
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Symantec Critical System Protection versions 5.2.9 before MP6
Symantec Data Center Security: Server Advanced versions 6.0.x before 6.0 MP1
Description
The issue allows remote authenticated users to execute arbitrary commands by leveraging client-system access to upload a log file. This is related to the Agent Control Interface in the management server.
Recommendations
For Symantec Critical System Protection versions 5.2.9 before MP6, update to a version that includes MP6 or later.
For Symantec Data Center Security: Server Advanced versions 6.0.x before 6.0 MP1, update to version 6.0 MP1 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Symantec Critical System Protection
Symantec Data Center Security: Server Advanced