PT-2016-4028 · Symantec · Data Center Security: Server Advanced Server+2

Published

2016-06-08

·

Updated

2021-09-09

·

CVE-2015-8798

CVSS v2.0

7.7

High

VectorAV:A/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Symantec Embedded Security: Critical System Protection (SES:CSP) versions 1.0.x through 1.0 before MP5 Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) version 6.5.0 before MP1 Critical System Protection (SCSP) versions prior to 5.2.9 MP6 Data Center Security: Server Advanced Server (DCS:SA) versions 6.x through 6.5 before MP1 and version 6.6 before MP1 Data Center Security: Server Advanced Server and Agents (DCS:SA) versions prior to 6.6 MP1
Description A directory traversal issue in the Management Server allows remote authenticated users to execute arbitrary code via unspecified vectors.
Recommendations For Symantec Embedded Security: Critical System Protection (SES:CSP) versions 1.0.x, update to 1.0 MP5 or later. For Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) version 6.5.0, update to MP1 or later. For Critical System Protection (SCSP), update to 5.2.9 MP6 or later. For Data Center Security: Server Advanced Server (DCS:SA) versions 6.x, update to 6.5 MP1 or later, and for version 6.6, update to MP1 or later. For Data Center Security: Server Advanced Server and Agents (DCS:SA), update to 6.6 MP1 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-8798

Affected Products

Critical System Protection
Data Center Security: Server Advanced Server
Symantec Embedded Security: Critical System Protection