Vulnerability Description
Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly to the Client User Interface Password protection and Policy Import/Export Password protection, if it has been enabled.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Symantec Endpoint Protection | < 14.3.5.1 |
References
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/conPermissions RequiredVendor Advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/conPermissions RequiredVendor Advisory
FAQ
What is CVE-2022-37017?
CVE-2022-37017 is a vulnerability with a CVSS score of 7.5 (HIGH). Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a t...
How severe is CVE-2022-37017?
CVE-2022-37017 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-37017?
Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Symantec Endpoint Protection.