CVE-2016-5304 EXPLOIT
6.8
MEDIUM · CVSS 3.0 · EPSS 4.1% (pctl 90)
Patch early
A public exploit exists.
Description
Open redirect vulnerability in a report-routing component in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Scoring
| CVSS | 6.8 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N |
| EPSS | 4.12% — more likely to be exploited than 90% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2016-06-30 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| symantec | endpoint protection manager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Symantec Endpoint Protection Manager 12.1 - Multiple Vulnerabilities | 2016-06-29 |
References
- http://www.securityfocus.com/bid/91447
- http://www.securitytracker.com/id/1036196
- https://www.exploit-db.com/exploits/40041/
- https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160628_01
- http://www.securityfocus.com/bid/91447
- http://www.securitytracker.com/id/1036196
- https://www.exploit-db.com/exploits/40041/
- https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160628_01
→ the Explorer · watch your stack · NVD