// For flags

CVE-2013-5009

 

Severity Score

7.4
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Management Console in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business Edition 12.x before 12.1.2 RU2 does not properly perform authentication, which allows remote authenticated users to gain privileges by leveraging access to a limited-admin account.

La Consola de Administración en Symantec Endpoint Protection (SEP) 11.x anteriores a 11.0.7.4 y 12.x anteriores a 12.1.2 RU2 y Endpoint Protection Small Business Edition 12.x anteriores a 12.1.2 RU2 no realizan la autenticación de forma apropiada , lo cual permite a usuarios remotos autenticados obtener privilegios aprovechando el acceso a una cuenta de administrador limitada.

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
Medium
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-07-29 CVE Reserved
  • 2014-01-10 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
<= 11.0.7.3
Search vendor "Symantec" for product "Endpoint Protection" and version " <= 11.0.7.3"
-
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0"
-
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0"
ru5
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0"
ru6
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0"
ru6a
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0"
ru6mp1
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0"
ru6mp2
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0.1
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0.1"
-
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0.1
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0.1"
mp1
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0.1
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0.1"
mp2
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0.2
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0.2"
-
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0.2
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0.2"
mp1
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0.2
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0.2"
mp2
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0.4
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0.4"
-
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0.4
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0.4"
mp1a
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0.4
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0.4"
mp2
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0.3001
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0.3001"
-
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0.6000
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0.6000"
-
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0.6100
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0.6100"
-
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0.6200
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0.6200"
-
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0.6200.754
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0.6200.754"
-
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0.6300
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0.6300"
-
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0.7000
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0.7000"
-
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
11.0.7100
Search vendor "Symantec" for product "Endpoint Protection" and version "11.0.7100"
-
Affected