3.3
CVE-2015-8801
- EPSS 0.06%
- Veröffentlicht 30.06.2016 23:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle secure@symantec.com
- CVE-Watchlists
- Unerledigt
Race condition in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6 MP5 allows local users to bypass intended restrictions on USB file transfer by conducting filesystem operations before the SEP device manager recognizes a new USB device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Symantec ≫ Endpoint Protection Manager Updatemp4 Version <= 12.1.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.154 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 2.9 | 0.4 | 2.5 |
CVSS:3.0/AV:P/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
|
| nvd@nist.gov | 3.3 | 3.4 | 4.9 |
AV:L/AC:M/Au:N/C:P/I:P/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.