Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-37017


Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly to the Client User Interface Password protection and Policy Import/Export Password protection, if it has been enabled.


Published

2022-12-01T14:15:11.973

Last Modified

2025-04-24T21:15:18.830

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application broadcom symantec_endpoint_protection < 14.3.5.1 Yes

References