First published: Mon Aug 15 2011(Updated: )
Cross-site request forgery (CSRF) vulnerability in the Web Interface in the Endpoint Protection Manager in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.6300 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Endpoint Protection | =11.0.6300 | |
Symantec Endpoint Protection | =11.0.6200.754 | |
Symantec Endpoint Protection | =11.0.6100 | |
Symantec Endpoint Protection | =11.0.6000 | |
Symantec Endpoint Protection | =11.0.6200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0551 is considered a high severity vulnerability as it allows attackers to hijack administrator authentication.
To fix CVE-2011-0551, update your Symantec Endpoint Protection to the latest version that has patched this CSRF vulnerability.
CVE-2011-0551 affects Symantec Endpoint Protection versions 11.0.6000 to 11.0.6300.
CVE-2011-0551 enables cross-site request forgery (CSRF) attacks that can compromise administrative accounts.
Administrators using vulnerable versions of Symantec Endpoint Protection are primarily affected by CVE-2011-0551.