CyberSec.Space Logo
CVEブラウザに戻る

CVE-2015-8157

HIGH
8.8
CVSS Severity Score
EPSS Score0.1330%
EPSS Percentile3.24th
Published2016年6月8日
Last Modified2026年5月6日

Vulnerability Description

SQL injection vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security: Server Advanced Server (DCS:SA) 6.x before 6.5 MP1 and 6.6 before MP1, and Data Center Security: Server Advanced Server and Agents (DCS:SA) through 6.6 MP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

Affected Platforms (CPE)

📦
Broadcom

Symantec Critical System Protection

<= 5.2.9
📦
Broadcom

Symantec Data Center Security Server

= 6.5.0
📦
Broadcom

Symantec Data Center Security Server

= 6.6.0
📦
Broadcom

Symantec Data Center Security Server And Agents

<= 6.6.0
💻
Broadcom

Symantec Embedded Security Critical System Protection

<= 1.0
💻
Broadcom

Symantec Embedded Security Critical System Protection For Controllers And Devices

<= 6.5.0

References & Advisories

関連する脆弱性情報