CVE-2014-1643: Symantec Encryption Management Server
Medium severity, CVSS 4.0. EPSS: 0.7% chance of exploitation in the next 30 days.
The Web Email Protection component in Symantec Encryption Management Server (aka PGP Universal Server) before 3.3.2 allows remote authenticated users to read the stored outbound e-mail messages of arbitrary users via a modified URL.
Affected products
- Symantec Encryption Management Server: up to and including 3.3.1; version 3.3.0 only
Published 2014-02-07. Last modified 2026-06-17.