First published: Tue Jan 23 2018(Updated: )
Symantec Reporter 9.5 prior to 9.5.4.1 and 10.1 prior to 10.1.5.5 does not restrict excessive authentication attempts for management interface users. A remote attacker can use brute force search to guess a user password and gain access to Reporter.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Reporter | >=9.5<9.5.4.1 | |
Symantec Reporter | =10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-15531 is rated as critical with a score of 9.8.
To fix CVE-2017-15531, upgrade your Symantec Reporter software to version 9.5.4.1 or 10.1.5.5 or later.
CVE-2017-15531 addresses the lack of restriction on excessive authentication attempts for management interface users.
CVE-2017-15531 affects users of Symantec Reporter versions prior to 9.5.4.1 and 10.1 prior to 10.1.5.5.
Yes, CVE-2017-15531 can be exploited remotely by an attacker using brute force techniques to guess user passwords.