CVE-2015-8800

HIGHCVSS 7.3/10EPSS 1.36%

Last modified

CVE-2015-8800 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security: Server Advanced Server (DCS:SA) 6.x before 6.5 MP1 and 6.6 before MP1, and Data Center Security: Server Advanced Server and Agents (DCS:SA) through 6.6 MP1 allow remote authenticated users to conduct argument-injection attacks by leveraging certain named-pipe access.. EPSS estimates a 1.36% chance of exploitation in the next 30 days.

Description

Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security: Server Advanced Server (DCS:SA) 6.x before 6.5 MP1 and 6.6 before MP1, and Data Center Security: Server Advanced Server and Agents (DCS:SA) through 6.6 MP1 allow remote authenticated users to conduct argument-injection attacks by leveraging certain named-pipe access.

Metrics

CVSS 3.1
7.3/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H

EPSS Probability
1.36%

68.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
BroadcomSymantec Critical System Protection5.2.9
BroadcomSymantec Data Center Security Server6.5.0
BroadcomSymantec Data Center Security Server6.6.0
BroadcomSymantec Data Center Security Server And Agents6.6.0
BroadcomSymantec Embedded Security Critical System Protection1.0
BroadcomSymantec Embedded Security Critical System Protection For Controllers And Devices6.5.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-8800?
Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security: Server Advanced Server (DCS:SA) 6.x before 6.5 MP1 and 6.6 before MP1, and Data Center Security: Server Advanced Server and Agents (DCS:SA) through 6.6 MP1 allow remote authenticated users to conduct argument-injection attacks by leveraging certain named-pipe access.
How severe is CVE-2015-8800?
CVE-2015-8800 has a CVSS score of 7.3/10 (HIGH severity). The EPSS model estimates a 1.36% probability of exploitation in the next 30 days.
How do I fix CVE-2015-8800?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-8800?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST