Vulnerability Description
Symantec Industrial Control System Protection (ICSP), versions 6.x.x, may be susceptible to an unauthorized access issue that could potentially allow a threat actor to create or modify application user accounts without proper authentication.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Symantec | Industrial Control System Protection | >= 6.0.0, < 6.1.1.123 |
Related Weaknesses (CWE)
References
- https://support.symantec.com/us/en/article.SYMSA1500.htmlVendor Advisory
- https://support.symantec.com/us/en/article.SYMSA1500.htmlVendor Advisory
FAQ
What is CVE-2019-18380?
CVE-2019-18380 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Symantec Industrial Control System Protection (ICSP), versions 6.x.x, may be susceptible to an unauthorized access issue that could potentially allow a threat actor to create or modify application use...
How severe is CVE-2019-18380?
CVE-2019-18380 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-18380?
Check the references section above for vendor advisories and patch information. Affected products include: Symantec Industrial Control System Protection.