6.8

CVE-2018-12244

SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby an application or website allows untrusted input into CSV files.

Data is provided by the National Vulnerability Database (NVD)
SymantecEndpoint Protection Version11.0 SwPlatformmacos
SymantecEndpoint Protection Version11.0 Updatemr1 SwPlatformmacos
SymantecEndpoint Protection Version11.0 Updatemr2 SwPlatformmacos
SymantecEndpoint Protection Version11.0 Updatemr3 SwPlatformmacos
SymantecEndpoint Protection Version11.0 Updatemr4 SwPlatformmacos
SymantecEndpoint Protection Version11.0 Updatemr4-mp2 SwPlatformmacos
SymantecEndpoint Protection Version11.0 Updateru5 SwPlatformmacos
SymantecEndpoint Protection Version11.0 Updateru6 SwPlatformmacos
SymantecEndpoint Protection Version11.0 Updateru6-mp1 SwPlatformmacos
SymantecEndpoint Protection Version11.0 Updateru6-mp2 SwPlatformmacos
SymantecEndpoint Protection Version11.0 Updateru6-mp3 SwPlatformmacos
SymantecEndpoint Protection Version11.0 Updateru6a SwPlatformmacos
SymantecEndpoint Protection Version11.0 Updateru7 SwPlatformmacos
SymantecEndpoint Protection Version11.0 Updateru7-mp1 SwPlatformmacos
SymantecEndpoint Protection Version11.0 Updateru7-mp2 SwPlatformmacos
SymantecEndpoint Protection Version11.0 Updateru7-mp4 SwPlatformmacos
SymantecEndpoint Protection Version11.0 Updateru7-mp4a SwPlatformmacos
SymantecEndpoint Protection Version11.0 Updatery7-mp3 SwPlatformmacos
SymantecEndpoint Protection Version12.1 SwPlatformmacos
SymantecEndpoint Protection Version12.1 Updateru1 SwPlatformmacos
SymantecEndpoint Protection Version12.1 Updateru1-mp1 SwPlatformmacos
SymantecEndpoint Protection Version12.1 Updateru2 SwPlatformmacos
SymantecEndpoint Protection Version12.1 Updateru2-mp1 SwPlatformmacos
SymantecEndpoint Protection Version12.1 Updateru3 SwPlatformmacos
SymantecEndpoint Protection Version12.1 Updateru4 SwPlatformmacos
SymantecEndpoint Protection Version12.1 Updateru4-mp1 SwPlatformmacos
SymantecEndpoint Protection Version12.1 Updateru4-mp1a SwPlatformmacos
SymantecEndpoint Protection Version12.1 Updateru4-mp1b SwPlatformmacos
SymantecEndpoint Protection Version12.1 Updateru4a SwPlatformmacos
SymantecEndpoint Protection Version12.1 Updateru5 SwPlatformmacos
SymantecEndpoint Protection Version12.1 Updateru6 SwPlatformmacos
SymantecEndpoint Protection Version12.1 Updateru6-mp1 SwPlatformmac_os_x
SymantecEndpoint Protection Version12.1 Updateru6-mp10 SwPlatformmacos
SymantecEndpoint Protection Version12.1 Updateru6-mp2 SwPlatformmacos
SymantecEndpoint Protection Version12.1 Updateru6-mp3 SwPlatformmac_os_x
SymantecEndpoint Protection Version12.1 Updateru6-mp4 SwPlatformmacos
SymantecEndpoint Protection Version12.1 Updateru6-mp5 SwPlatformmac_os_x
SymantecEndpoint Protection Version12.1 Updateru6-mp6 SwPlatformmacos
SymantecEndpoint Protection Version12.1 Updateru6-mp7 SwPlatformmacos
SymantecEndpoint Protection Version12.1 Updateru6-mp8 SwPlatformmacos
SymantecEndpoint Protection Version14 SwPlatformmacos
SymantecEndpoint Protection Version14 Updatemp1 SwPlatformmacos
SymantecEndpoint Protection Version14.0.0 Updatemp2 SwPlatformmacos
SymantecEndpoint Protection Version14.0.1 SwPlatformmacos
SymantecEndpoint Protection Version14.0.1 Updatemp1 SwPlatformmacos
SymantecEndpoint Protection Version14.0.1 Updatemp2 SwPlatformmacos
SymantecEndpoint Protection Version14.2 SwPlatformmacos
SymantecEndpoint Protection Version14.2 Updatemp1 SwPlatformmacos
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.38% 0.584
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.3 2.8 3.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-1236 Improper Neutralization of Formula Elements in a CSV File

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.