CVE-2016-3650: Symantec Endpoint Protection Manager

High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.

Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to discover credentials via a brute-force attack.

Affected products

  • Symantec Endpoint Protection Manager: up to and including 12.1.6

Published 2016-06-30. Last modified 2026-06-17.