CVE-2013-5016: High severity Broadcom Symantec Critical System Protection vulnerability
Published May 8, 2014
·Updated
Symantec Critical System Protection (SCSP) before 5.2.9, when installed on an unpatched Windows Server 2003 R2 platform, allows remote attackers to bypass policy settings via unspecified vectors.
Affected Software
4 affected components
Broadcom Symantec Critical System Protection<=5.2.8
Microsoft Windows 2003 Server=r2
All of the following
Broadcom Symantec Critical System Protection<=5.2.8
Microsoft Windows 2003 Server=r2
Event History
May 8, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-5016?
CVE-2013-5016 is classified as a medium severity vulnerability.
2
How do I fix CVE-2013-5016?
To fix CVE-2013-5016, upgrade Symantec Critical System Protection to version 5.2.9 or higher.
3
What platforms are affected by CVE-2013-5016?
CVE-2013-5016 affects Symantec Critical System Protection installed on unpatched Windows Server 2003 R2.
4
Can CVE-2013-5016 be exploited remotely?
Yes, CVE-2013-5016 allows remote attackers to bypass policy settings.
5
What should I do if I am running an affected version of Symantec Critical System Protection?
If you are running an affected version, it is critical to upgrade to the patched version as soon as possible.