CVE-2016-3648: Symantec Endpoint Protection Manager
High severity, CVSS 8.8. EPSS: 2.3% chance of exploitation in the next 30 days.
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to bypass the Authentication Lock protection mechanism, and conduct brute-force password-guessing attacks against management-console accounts, by entering data into the authorization window.
Affected products
- Symantec Endpoint Protection Manager: up to and including 12.1.6
Published 2016-06-30. Last modified 2026-06-17.