peter bassill · operator
$ cve CVE-2016-3653 JSON

CVE-2016-3653 EXPLOIT

8.0
HIGH · CVSS 3.0 · EPSS 1.3% (pctl 71)

Patch early

A public exploit exists.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users to hijack the authentication of arbitrary users.

Scoring

CVSS8.0 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS1.34% — more likely to be exploited than 71% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2016-06-30
Last modified2026-06-17

Affected (1)

VendorProduct
symantecendpoint protection manager

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD