CVE-2019-18376

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
10/04/2020
Last modified:
21/07/2021

Description

A CSRF token disclosure vulnerability allows a remote attacker, with access to an authenticated Management Center (MC) user's web browser history or a network device that intercepts/logs traffic to MC, to obtain CSRF tokens and use them to perform CSRF attacks against MC.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:symantec:management_center:2.2:*:*:*:*:*:*:*
cpe:2.3:a:symantec:management_center:2.3:*:*:*:*:*:*:*
cpe:2.3:a:symantec:management_center:2.4:*:*:*:*:*:*:*