CVE-2007-2375
Last modified
CVE-2007-2375 is a vulnerability of currently unknown severity. The agent remote upgrade interface in Symantec Enterprise Security Manager (ESM) before 20070405 does not verify the authenticity of upgrades, which allows remote attackers to execute arbitrary code via software that implements the agent upgrade protocol.. EPSS estimates a 5.58% chance of exploitation in the next 30 days.
Description
The agent remote upgrade interface in Symantec Enterprise Security Manager (ESM) before 20070405 does not verify the authenticity of upgrades, which allows remote attackers to execute arbitrary code via software that implements the agent upgrade protocol.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Symantec | Enterprise Security Manager | 5.5.3 |
| Symantec | Enterprise Security Manager | 6.0 |
| Symantec | Enterprise Security Manager | 6.5 |
| Symantec | Enterprise Security Manager | 6.5.1 |
| Symantec | Enterprise Security Manager | 6.5.2 |
References
- http://secunia.com/advisories/24767Patch, Vendor Advisory
- http://secunia.com/advisories/24767Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-2375?
How severe is CVE-2007-2375?
How do I fix CVE-2007-2375?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-2369Directory traversal vulnerability in picture.php in WebSPELL…
- CVE-2007-2370SQL injection vulnerability in index.php in the John Mordo J…
- CVE-2007-2371admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 bet…
- CVE-2007-2372admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 …
- CVE-2007-2373SQL injection vulnerability in viewcat.php in the WF-Links (…
- CVE-2007-2374Unspecified vulnerability in Microsoft Windows 2000, XP, and…
- CVE-2007-2376The Dojo framework exchanges data using JavaScript Object No…
- CVE-2007-2377The Getahead Direct Web Remoting (DWR) framework 1.1.4 excha…
- CVE-2007-2378The Google Web Toolkit (GWT) framework exchanges data using …
- CVE-2007-2379The jQuery framework exchanges data using JavaScript Object …
- CVE-2007-2380The Microsoft Atlas framework exchanges data using JavaScrip…
- CVE-2007-2381The MochiKit framework exchanges data using JavaScript Objec…
Are you affected by CVE-2007-2375?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
