CVE-2016-3647: Symantec Endpoint Protection Manager
High severity, CVSS 7.7. EPSS: 1.9% chance of exploitation in the next 30 days.
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and trigger network traffic to arbitrary intranet hosts, via a crafted request.
Affected products
- Symantec Endpoint Protection Manager: up to and including 12.1.6
Published 2016-06-30. Last modified 2026-06-17.