CVE-2015-8801
Last modified
CVE-2015-8801 is a vulnerability of currently unknown severity. Race condition in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6 MP5 allows local users to bypass intended restrictions on USB file transfer by conducting filesystem operations before the SEP device manager recognizes a new USB device.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Race condition in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6 MP5 allows local users to bypass intended restrictions on USB file transfer by conducting filesystem operations before the SEP device manager recognizes a new USB device.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Symantec | Endpoint Protection Manager | <= 12.1.6 | Mp4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-8801?
How severe is CVE-2015-8801?
How do I fix CVE-2015-8801?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-8795Multiple cross-site scripting (XSS) vulnerabilities in the A…
- CVE-2015-8796Cross-site scripting (XSS) vulnerability in webapp/web/js/sc…
- CVE-2015-8797Cross-site scripting (XSS) vulnerability in webapp/web/js/sc…
- CVE-2015-8798Directory traversal vulnerability in the Management Server i…8
- CVE-2015-8799Directory traversal vulnerability in the Management Server i…7.6
- CVE-2015-8800Symantec Embedded Security: Critical System Protection (SES:…7.3
- CVE-2015-8802Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-8803The ecc_256_modp function in ecc-256.c in Nettle before 3.2 …
- CVE-2015-8804x86_64/ecc-384-modp.asm in Nettle before 3.2 does not proper…
- CVE-2015-8805The ecc_256_modq function in ecc-256.c in Nettle before 3.2 …
- CVE-2015-8806dict.c in libxml2 allows remote attackers to cause a denial …7.5
- CVE-2015-8807Cross-site scripting (XSS) vulnerability in the _renderVarIn…
Are you affected by CVE-2015-8801?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
