CVE-2017-15531

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
23/01/2018
Last modified:
04/05/2018

Description

Symantec Reporter 9.5 prior to 9.5.4.1 and 10.1 prior to 10.1.5.5 does not restrict excessive authentication attempts for management interface users. A remote attacker can use brute force search to guess a user password and gain access to Reporter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:symantec:reporter:*:*:*:*:*:*:*:* 9.5 (including) 9.5.4.1 (excluding)
cpe:2.3:a:symantec:reporter:10.1:*:*:*:*:*:*:*