CVE-2014-7288: Symantec Encryption Management Server

High severity, CVSS 9.0. EPSS: 8.1% chance of exploitation in the next 30 days.

Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell commands via a crafted command line in a database-backup restore action.

Affected products

  • Symantec Encryption Management Server: up to and including 3.3.2
  • Symantec Pgp Universal Server: up to and including 3.3.2

Published 2015-02-01. Last modified 2026-06-17.