// For flags

CVE-2018-5243

 

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Symantec Encryption Management Server (SEMS) product, prior to version 3.4.2 MP1, may be susceptible to a denial of service (DoS) exploit. A DoS attack is a type of attack whereby the perpetrator attempts to make a particular machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a specific host within a network.

El producto Symantec Encryption Management Server (SEMS) en versiones anteriores a la versión 3.4.2 MP1, puede ser susceptible a una denegación de servicio (DoS). Un ataque DoS es un tipo de ataque en el que el infractor intenta hacer que un dispositivo o recurso de red en concreto se vuelva inutilizable para sus usuarios originales mediante la interrupción temporal o indefinida de un host específico en una red.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-01-05 CVE Reserved
  • 2018-08-20 CVE Published
  • 2024-04-01 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-400: Uncontrolled Resource Consumption
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Symantec
Search vendor "Symantec"
Encryption Management Server
Search vendor "Symantec" for product "Encryption Management Server"
<= 3.4.2
Search vendor "Symantec" for product "Encryption Management Server" and version " <= 3.4.2"
-
Affected