CVE-2014-9226: High severity broadcom symantec critical system protection vulnerability
The management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows local users to bypass intended Protection Policies via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9226?
CVE-2014-9226 is classified as a medium severity vulnerability.
How do I fix CVE-2014-9226?
To mitigate CVE-2014-9226, ensure that you update Symantec Critical System Protection to version 5.2.9 MP7 or higher and Symantec Data Center Security to version 6.0 MP2 or higher.
What are the affected products for CVE-2014-9226?
The affected products for CVE-2014-9226 include Symantec Critical System Protection 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced 6.0.x through 6.0 MP1.
Who is at risk from CVE-2014-9226?
Local users of Symantec Critical System Protection and Symantec Data Center Security who have access to the management server are at risk from CVE-2014-9226.
What attack vectors are associated with CVE-2014-9226?
CVE-2014-9226 allows local users to bypass Protection Policies through unspecified vectors.