CVE-2022-37017

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/12/2022
Last modified:
24/04/2025

Description

Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly to the Client User Interface Password protection and Policy Import/Export Password protection, if it has been enabled.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:broadcom:symantec_endpoint_protection:*:*:*:*:*:windows:*:* 14.3.5.1 (excluding)