Symantec
Symantec Encryption Management Server: vulnerabilities and CVEs
Symantec Encryption Management Server has 9 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs9
Last 12 months0
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5243 | High (7.5) | 1.8% | — | Aug 20, 2018 | The Symantec Encryption Management Server (SEMS) product, prior to version 3.4.2 MP1, may be susceptible to a denial of service (DoS) exploit. A DoS attack is a type of attack whereby the perpetrator attempts to make a… |
| CVE-2015-8151 | Critical (9.1) | 1.6% | — | Feb 18, 2016 | Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote authenticated users to execute arbitrary OS commands by leveraging console administrator access. |
| CVE-2015-8150 | High (7.8) | 0.28% | — | Feb 18, 2016 | Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows local users to obtain root access by modifying a batch file. |
| CVE-2015-8149 | High (7.5) | 1.7% | — | Feb 18, 2016 | The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to cause a denial of service (heap memory corruption and service outage) via crafted requests. |
| CVE-2015-8148 | High (7.5) | 1.6% | — | Feb 18, 2016 | The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to obtain sensitive information about administrator accounts via a modified request. |
| CVE-2014-7288 | High (9) | 8.1% | — | Feb 1, 2015 | Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell commands via a crafted command line in a database-backup restore… |
| CVE-2014-7287 | Medium (5) | 1.1% | — | Feb 1, 2015 | The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID… |
| CVE-2014-1643 | Medium (4) | 0.75% | — | Feb 7, 2014 | The Web Email Protection component in Symantec Encryption Management Server (aka PGP Universal Server) before 3.3.2 allows remote authenticated users to read the stored outbound e-mail messages of arbitrary users via a… |
| CVE-2013-4674 | Medium (4.3) | 0.89% | — | Jul 31, 2013 | Cross-site scripting (XSS) vulnerability in the Web Email Protection component in Symantec Encryption Management Server (formerly Symantec PGP Universal Server) before 3.3.0 MP2 allows remote authenticated users to… |