CVE-2016-3647: Symantec Endpoint Protection Manager

High severity, CVSS 7.7. EPSS: 1.9% chance of exploitation in the next 30 days.

Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and trigger network traffic to arbitrary intranet hosts, via a crafted request.

Affected products

  • Symantec Endpoint Protection Manager: up to and including 12.1.6

Published 2016-06-30. Last modified 2026-06-17.