APP: Symantec Workspace Streaming XML-RPC Arbitrary File Upload

This signature detects attempts to exploit a known vulnerability against Symantec Workspace. A successful attack can lead to the upload of an arbitrary file.

Extended Description

The server in Symantec Workspace Streaming (SWS) before 7.5.0.749 allows remote attackers to access files and functionality by sending a crafted XMLRPC request over HTTPS.

Affected Products

Symantec workspace_streaming

Short Name
APP:SYMC:WORKSPACE-FILE-UPLOAD
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
Arbitrary CVE-2014-1649 File Streaming Symantec Upload Workspace XML-RPC bid:67189
Release Date
06/09/2014
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Symantec

CVSS Score

7.9

Found a potential security threat?