Lucene search

K
cveSymantecCVE-2018-12244
HistoryApr 25, 2019 - 7:29 p.m.

CVE-2018-12244

2019-04-2519:29:00
CWE-1236
symantec
web.nvd.nist.gov
28
cve-2018-12244
sep
mac client
vulnerability
csv
dde injection
formula injection
nvd
information security

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

AI Score

6.5

Confidence

High

EPSS

0.001

Percentile

31.0%

SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby an application or website allows untrusted input into CSV files.

Affected configurations

Nvd
Node
symantecendpoint_protectionMatch11.0macos
OR
symantecendpoint_protectionMatch11.0mr1macos
OR
symantecendpoint_protectionMatch11.0mr2macos
OR
symantecendpoint_protectionMatch11.0mr3macos
OR
symantecendpoint_protectionMatch11.0mr4macos
OR
symantecendpoint_protectionMatch11.0mr4-mp2macos
OR
symantecendpoint_protectionMatch11.0ru5macos
OR
symantecendpoint_protectionMatch11.0ru6macos
OR
symantecendpoint_protectionMatch11.0ru6-mp1macos
OR
symantecendpoint_protectionMatch11.0ru6-mp2macos
OR
symantecendpoint_protectionMatch11.0ru6-mp3macos
OR
symantecendpoint_protectionMatch11.0ru6amacos
OR
symantecendpoint_protectionMatch11.0ru7macos
OR
symantecendpoint_protectionMatch11.0ru7-mp1macos
OR
symantecendpoint_protectionMatch11.0ru7-mp2macos
OR
symantecendpoint_protectionMatch11.0ru7-mp4macos
OR
symantecendpoint_protectionMatch11.0ru7-mp4amacos
OR
symantecendpoint_protectionMatch11.0ry7-mp3macos
OR
symantecendpoint_protectionMatch12.1macos
OR
symantecendpoint_protectionMatch12.1ru1macos
OR
symantecendpoint_protectionMatch12.1ru1-mp1macos
OR
symantecendpoint_protectionMatch12.1ru2macos
OR
symantecendpoint_protectionMatch12.1ru2-mp1macos
OR
symantecendpoint_protectionMatch12.1ru3macos
OR
symantecendpoint_protectionMatch12.1ru4macos
OR
symantecendpoint_protectionMatch12.1ru4-mp1macos
OR
symantecendpoint_protectionMatch12.1ru4-mp1amacos
OR
symantecendpoint_protectionMatch12.1ru4-mp1bmacos
OR
symantecendpoint_protectionMatch12.1ru4amacos
OR
symantecendpoint_protectionMatch12.1ru5macos
OR
symantecendpoint_protectionMatch12.1ru6macos
OR
symantecendpoint_protectionMatch12.1ru6-mp1mac_os_x
OR
symantecendpoint_protectionMatch12.1ru6-mp10macos
OR
symantecendpoint_protectionMatch12.1ru6-mp2macos
OR
symantecendpoint_protectionMatch12.1ru6-mp3mac_os_x
OR
symantecendpoint_protectionMatch12.1ru6-mp4macos
OR
symantecendpoint_protectionMatch12.1ru6-mp5mac_os_x
OR
symantecendpoint_protectionMatch12.1ru6-mp6macos
OR
symantecendpoint_protectionMatch12.1ru6-mp7macos
OR
symantecendpoint_protectionMatch12.1ru6-mp8macos
OR
symantecendpoint_protectionMatch14macos
OR
symantecendpoint_protectionMatch14mp1macos
OR
symantecendpoint_protectionMatch14.0.0mp2macos
OR
symantecendpoint_protectionMatch14.0.1macos
OR
symantecendpoint_protectionMatch14.0.1mp1macos
OR
symantecendpoint_protectionMatch14.0.1mp2macos
OR
symantecendpoint_protectionMatch14.2macos
OR
symantecendpoint_protectionMatch14.2mp1macos
VendorProductVersionCPE
symantecendpoint_protection11.0cpe:2.3:a:symantec:endpoint_protection:11.0:*:*:*:*:macos:*:*
symantecendpoint_protection11.0cpe:2.3:a:symantec:endpoint_protection:11.0:mr1:*:*:*:macos:*:*
symantecendpoint_protection11.0cpe:2.3:a:symantec:endpoint_protection:11.0:mr2:*:*:*:macos:*:*
symantecendpoint_protection11.0cpe:2.3:a:symantec:endpoint_protection:11.0:mr3:*:*:*:macos:*:*
symantecendpoint_protection11.0cpe:2.3:a:symantec:endpoint_protection:11.0:mr4:*:*:*:macos:*:*
symantecendpoint_protection11.0cpe:2.3:a:symantec:endpoint_protection:11.0:mr4-mp2:*:*:*:macos:*:*
symantecendpoint_protection11.0cpe:2.3:a:symantec:endpoint_protection:11.0:ru5:*:*:*:macos:*:*
symantecendpoint_protection11.0cpe:2.3:a:symantec:endpoint_protection:11.0:ru6:*:*:*:macos:*:*
symantecendpoint_protection11.0cpe:2.3:a:symantec:endpoint_protection:11.0:ru6-mp1:*:*:*:macos:*:*
symantecendpoint_protection11.0cpe:2.3:a:symantec:endpoint_protection:11.0:ru6-mp2:*:*:*:macos:*:*
Rows per page:
1-10 of 481

CNA Affected

[
  {
    "product": "Symantec Endpoint Protection (Mac Client)",
    "vendor": "Symantec Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "Prior to and including 12.1 RU6 MP9"
      },
      {
        "status": "affected",
        "version": "Prior to 14.2 RU1"
      }
    ]
  }
]

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

AI Score

6.5

Confidence

High

EPSS

0.001

Percentile

31.0%

Related for CVE-2018-12244