HTTP: Symantec Encryption Management Server Local Command Injection

This signature detects attempts to exploit a known vulnerability against Symantec Encryption Management. A successful exploit can lead to remote command execution.

Extended Description

Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell commands via a crafted command line in a database-backup restore action.

Affected Products

Symantec encryption_management_server

Short Name
HTTP:MISC:SYMANTEC-COMMAND-EXEC
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2014-7288 Command Encryption Injection Local Management Server Symantec bid:72308
Release Date
03/02/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Symantec

CVSS Score

9.0

Found a potential security threat?