CVE-2020-5821
Severity CVSS v4.0:
Pending analysis
Type:
CWE-427
Uncontrolled Search Path Element
Publication date:
11/02/2020
Last modified:
21/07/2021
Description
Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a DLL injection vulnerability, which is a type of issue whereby an individual attempts to execute their own code in place of legitimate code as a means to perform an exploit.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:symantec:endpoint_protection:11.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:endpoint_protection:11.0:mr1:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:endpoint_protection:11.0:mr2:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:endpoint_protection:11.0:mr3:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:endpoint_protection:11.0:mr4:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:endpoint_protection:11.0:mr4-mp1a:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:endpoint_protection:11.0:mr4-mp2:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:endpoint_protection:11.0:ru5:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:endpoint_protection:11.0:ru6:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:endpoint_protection:11.0:ru6-mp1:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:endpoint_protection:11.0:ru6-mp2:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:endpoint_protection:11.0:ru6-mp3:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:endpoint_protection:11.0:ru6a:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:endpoint_protection:11.0:ru7:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:endpoint_protection:11.0:ru7-mp1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



