SSL: Symantec Endpoint Protection Manager Cross-Site Scripting

This signature detects attempts to exploit a known vulnerability against Symantec Endpoint Protection Manager.This can lead to arbitrary script code execution in the context of the affected user.

Extended Description

Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Affected Products

Symantec endpoint_protection_manager

References

CVE: CVE-2016-3652

Short Name
SSL:SYMANTEC-ENDPOINT-XSS
Severity
Major
Recommended
True
Recommended Action
Drop
Category
SSL
Keywords
CVE-2016-3652 Cross-Site Endpoint Manager Protection Scripting Symantec
Release Date
07/25/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Symantec

CVSS Score

3.5

Found a potential security threat?