Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Symantec_critical_system_protection
(Broadcom)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 11 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2016-06-08 | CVE-2015-8798 | Directory traversal vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security: Server Advanced Server (DCS:SA) 6.x before 6.5 MP1 and 6.6 before MP1, and Data Center Security: Server Advanced Server and Agents (DCS:SA) through 6.6 MP1 allows remote... | Symantec_critical_system_protection, Symantec_data_center_security_server, Symantec_data_center_security_server_and_agents, Symantec_embedded_security_critical_system_protection, Symantec_embedded_security_critical_system_protection_for_controllers_and_devices | 8.0 | ||
2016-06-08 | CVE-2015-8157 | SQL injection vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security: Server Advanced Server (DCS:SA) 6.x before 6.5 MP1 and 6.6 before MP1, and Data Center Security: Server Advanced Server and Agents (DCS:SA) through 6.6 MP1 allows remote... | Symantec_critical_system_protection, Symantec_data_center_security_server, Symantec_data_center_security_server_and_agents, Symantec_embedded_security_critical_system_protection, Symantec_embedded_security_critical_system_protection_for_controllers_and_devices | 8.8 | ||
2016-06-08 | CVE-2015-8799 | Directory traversal vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security: Server Advanced Server (DCS:SA) 6.x before 6.5 MP1 and 6.6 before MP1, and Data Center Security: Server Advanced Server and Agents (DCS:SA) through 6.6 MP1 allows remote... | Symantec_critical_system_protection, Symantec_data_center_security_server, Symantec_data_center_security_server_and_agents, Symantec_embedded_security_critical_system_protection, Symantec_embedded_security_critical_system_protection_for_controllers_and_devices | 7.6 | ||
2016-06-08 | CVE-2015-8800 | Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security: Server Advanced Server (DCS:SA) 6.x before 6.5 MP1 and 6.6 before MP1, and Data Center Security: Server Advanced Server and Agents (DCS:SA) through 6.6 MP1 allow remote authenticated users to conduct argument-injection attacks by... | Symantec_critical_system_protection, Symantec_data_center_security_server, Symantec_data_center_security_server_and_agents, Symantec_embedded_security_critical_system_protection, Symantec_embedded_security_critical_system_protection_for_controllers_and_devices | 7.3 | ||
2015-01-21 | CVE-2014-9224 | Cross-site scripting (XSS) vulnerability in the ajaxswing webui in the Management Console server in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | Symantec_critical_system_protection, Data_center_security | N/A | ||
2015-01-21 | CVE-2014-9225 | The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to obtain sensitive server information via unspecified vectors. | Symantec_critical_system_protection, Data_center_security | N/A | ||
2015-01-21 | CVE-2014-9226 | The management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows local users to bypass intended Protection Policies via unspecified vectors. | Symantec_critical_system_protection, Data_center_security | N/A | ||
2014-05-08 | CVE-2013-5016 | Symantec Critical System Protection (SCSP) before 5.2.9, when installed on an unpatched Windows Server 2003 R2 platform, allows remote attackers to bypass policy settings via unspecified vectors. | Symantec_critical_system_protection | N/A | ||
2015-01-21 | CVE-2014-3440 | The Agent Control Interface in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenticated users to execute arbitrary commands by leveraging client-system access to upload a log file. | Symantec_critical_system_protection, Data_center_security | N/A | ||
2015-01-21 | CVE-2014-7289 | SQL injection vulnerability in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenticated users to execute arbitrary SQL commands via a crafted HTTP request. | Symantec_critical_system_protection, Data_center_security | N/A |