CVE-2014-3437
Estado: ModificadaAlta (7.5)—💥 Exploit
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 8.54%
- Percentil entre todas las CVEs puntuadas: 95
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Publicado en Exploit-DB · Symantec Endpoint Protection 12.1.4023.4080 - Multiple Vulnerabilities (6/11/2014)
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://seclists.org/fulldisclosure/2014/Nov/7
- http://www.securityfocus.com/archive/1/533918/100/0/threaded
- http://www.securityfocus.com/bid/70843
- http://www.securitytracker.com/id/1031176
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20141105_00
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98525
- http://seclists.org/fulldisclosure/2014/Nov/7
- http://www.securityfocus.com/archive/1/533918/100/0/threaded
- http://www.securityfocus.com/bid/70843
- http://www.securitytracker.com/id/1031176
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20141105_00
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98525
JSON original (NVD)
Mostrar
{
"id": "CVE-2014-3437",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secure@symantec.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-11-07T11:55:03.033",
"references": [
{
"url": "http://seclists.org/fulldisclosure/2014/Nov/7",
"tags": [
"Exploit"
],
"source": "secure@symantec.com"
},
{
"url": "http://www.securityfocus.com/archive/1/533918/100/0/threaded",
"source": "secure@symantec.com"
},
{
"url": "http://www.securityfocus.com/bid/70843",
"source": "secure@symantec.com"
},
{
"url": "http://www.securitytracker.com/id/1031176",
"source": "secure@symantec.com"
},
{
"url": "http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20141105_00",
"tags": [
"Vendor Advisory"
],
"source": "secure@symantec.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/98525",
"source": "secure@symantec.com"
},
{
"url": "http://seclists.org/fulldisclosure/2014/Nov/7",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/533918/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/70843",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1031176",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20141105_00",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/98525",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue."
},
{
"lang": "es",
"value": "La consola de gestión en Symantec Endpoint Protection Manager (SEPM) 12.1 anterior a RU5 permite a atacantes remotos leer ficheros arbitrarios o enviar solicitudes TCP a servidores de intranet a través de datos XML que contienen una declaración de entidad externa en conjunto con una referencia de entidad, relacionado con un problema de entidad externa XML (XXE)."
}
],
"lastModified": "2026-06-17T00:08:10.953",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:symantec:endpoint_protection_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "04E4FA27-9009-4AB2-B845-96BF9E75312F",
"versionEndIncluding": "12.1.4"
},
{
"criteria": "cpe:2.3:a:symantec:endpoint_protection_manager:12.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "590E3332-512F-44D9-A67C-6F87F6C09D17"
},
{
"criteria": "cpe:2.3:a:symantec:endpoint_protection_manager:12.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AAC3C870-55F7-410C-9CF6-5DEAC742EA34"
},
{
"criteria": "cpe:2.3:a:symantec:endpoint_protection_manager:12.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E1F71A7F-B7BE-4CA8-B802-5151681BF59A"
},
{
"criteria": "cpe:2.3:a:symantec:endpoint_protection_manager:12.1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C583C973-8B2C-4279-BFFC-2B224954137C"
}
],
"operator": "OR"
}
]
}
],
"evaluatorComment": "<a href=\"http://cwe.mitre.org/data/definitions/611.html\" target=\"_blank\">CWE-611: Improper Restriction of XML External Entity Reference ('XXE')</a>",
"sourceIdentifier": "secure@symantec.com"
}