CVE-2015-6554: OS Command Injection
Published Nov 12, 2015
·Updated
Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP3 allows remote attackers to execute arbitrary OS commands via crafted data.
Affected Software
1 affected component
Symantec Endpoint Protection Manager<=12.1
Event History
Nov 12, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6554?
CVE-2015-6554 is classified as a high severity vulnerability that allows remote code execution.
2
How do I fix CVE-2015-6554?
To fix CVE-2015-6554, upgrade Symantec Endpoint Protection Manager to version 12.1-RU6-MP3 or later.
3
Who is affected by CVE-2015-6554?
CVE-2015-6554 affects users of Symantec Endpoint Protection Manager version 12.1 before 12.1-RU6-MP3.
4
What kind of attacks can be executed through CVE-2015-6554?
CVE-2015-6554 allows attackers to execute arbitrary operating system commands on the vulnerable machine.
5
Is there a workaround for CVE-2015-6554?
There is no official workaround for CVE-2015-6554, and upgrading is the recommended solution.