6.8

CVE-2018-12244

SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby an application or website allows untrusted input into CSV files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Symantec ≫ Endpoint Protection Version 11.0 SwPlatform macos
Symantec ≫ Endpoint Protection Version 11.0 Update mr1 SwPlatform macos
Symantec ≫ Endpoint Protection Version 11.0 Update mr2 SwPlatform macos
Symantec ≫ Endpoint Protection Version 11.0 Update mr3 SwPlatform macos
Symantec ≫ Endpoint Protection Version 11.0 Update mr4 SwPlatform macos
Symantec ≫ Endpoint Protection Version 11.0 Update mr4-mp2 SwPlatform macos
Symantec ≫ Endpoint Protection Version 11.0 Update ru5 SwPlatform macos
Symantec ≫ Endpoint Protection Version 11.0 Update ru6 SwPlatform macos
Symantec ≫ Endpoint Protection Version 11.0 Update ru6-mp1 SwPlatform macos
Symantec ≫ Endpoint Protection Version 11.0 Update ru6-mp2 SwPlatform macos
Symantec ≫ Endpoint Protection Version 11.0 Update ru6-mp3 SwPlatform macos
Symantec ≫ Endpoint Protection Version 11.0 Update ru6a SwPlatform macos
Symantec ≫ Endpoint Protection Version 11.0 Update ru7 SwPlatform macos
Symantec ≫ Endpoint Protection Version 11.0 Update ru7-mp1 SwPlatform macos
Symantec ≫ Endpoint Protection Version 11.0 Update ru7-mp2 SwPlatform macos
Symantec ≫ Endpoint Protection Version 11.0 Update ru7-mp4 SwPlatform macos
Symantec ≫ Endpoint Protection Version 11.0 Update ru7-mp4a SwPlatform macos
Symantec ≫ Endpoint Protection Version 11.0 Update ry7-mp3 SwPlatform macos
Symantec ≫ Endpoint Protection Version 12.1 SwPlatform macos
Symantec ≫ Endpoint Protection Version 12.1 Update ru1 SwPlatform macos
Symantec ≫ Endpoint Protection Version 12.1 Update ru1-mp1 SwPlatform macos
Symantec ≫ Endpoint Protection Version 12.1 Update ru2 SwPlatform macos
Symantec ≫ Endpoint Protection Version 12.1 Update ru2-mp1 SwPlatform macos
Symantec ≫ Endpoint Protection Version 12.1 Update ru3 SwPlatform macos
Symantec ≫ Endpoint Protection Version 12.1 Update ru4 SwPlatform macos
Symantec ≫ Endpoint Protection Version 12.1 Update ru4-mp1 SwPlatform macos
Symantec ≫ Endpoint Protection Version 12.1 Update ru4-mp1a SwPlatform macos
Symantec ≫ Endpoint Protection Version 12.1 Update ru4-mp1b SwPlatform macos
Symantec ≫ Endpoint Protection Version 12.1 Update ru4a SwPlatform macos
Symantec ≫ Endpoint Protection Version 12.1 Update ru5 SwPlatform macos
Symantec ≫ Endpoint Protection Version 12.1 Update ru6 SwPlatform macos
Symantec ≫ Endpoint Protection Version 12.1 Update ru6-mp1 SwPlatform mac_os_x
Symantec ≫ Endpoint Protection Version 12.1 Update ru6-mp10 SwPlatform macos
Symantec ≫ Endpoint Protection Version 12.1 Update ru6-mp2 SwPlatform macos
Symantec ≫ Endpoint Protection Version 12.1 Update ru6-mp3 SwPlatform mac_os_x
Symantec ≫ Endpoint Protection Version 12.1 Update ru6-mp4 SwPlatform macos
Symantec ≫ Endpoint Protection Version 12.1 Update ru6-mp5 SwPlatform mac_os_x
Symantec ≫ Endpoint Protection Version 12.1 Update ru6-mp6 SwPlatform macos
Symantec ≫ Endpoint Protection Version 12.1 Update ru6-mp7 SwPlatform macos
Symantec ≫ Endpoint Protection Version 12.1 Update ru6-mp8 SwPlatform macos
Symantec ≫ Endpoint Protection Version 14 SwPlatform macos
Symantec ≫ Endpoint Protection Version 14 Update mp1 SwPlatform macos
Symantec ≫ Endpoint Protection Version 14.0.0 Update mp2 SwPlatform macos
Symantec ≫ Endpoint Protection Version 14.0.1 SwPlatform macos
Symantec ≫ Endpoint Protection Version 14.0.1 Update mp1 SwPlatform macos
Symantec ≫ Endpoint Protection Version 14.0.1 Update mp2 SwPlatform macos
Symantec ≫ Endpoint Protection Version 14.2 SwPlatform macos
Symantec ≫ Endpoint Protection Version 14.2 Update mp1 SwPlatform macos
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.12% 0.619
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.3 2.8 3.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-1236 Improper Neutralization of Formula Elements in a CSV File

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

https://support.symantec.com/en_US/article.SYMSA1479.html
Vendor Advisory
https://www.securityfocus.com/bid/107999
Third Party Advisory
VDB Entry