CVE-2018-5240
Last modified
CVE-2018-5240 is a vulnerability of currently unknown severity. The Inventory Plugin for Symantec Management Agent prior to 7.6 POST HF7, 8.0 POST HF6, or 8.1 RU7 may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.. EPSS estimates a 1.10% chance of exploitation in the next 30 days.
Description
The Inventory Plugin for Symantec Management Agent prior to 7.6 POST HF7, 8.0 POST HF6, or 8.1 RU7 may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Symantec | Inventory | <= 7.6 | — |
| Symantec | Inventory | 8.0 | Hf6 |
| Symantec | Inventory | 8.1 | Ru7 |
References
- http://www.securityfocus.com/bid/104753Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041654Third Party Advisory
- https://support.symantec.com/en_US/article.SYMSA1456.htmlMitigation, Vendor Advisory
- http://www.securityfocus.com/bid/104753Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041654Third Party Advisory
- https://support.symantec.com/en_US/article.SYMSA1456.htmlMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5240?
How severe is CVE-2018-5240?
How do I fix CVE-2018-5240?
Are you affected by CVE-2018-5240?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
