CVE-2016-5306: Symantec Endpoint Protection Manager

Medium severity, CVSS 5.3. EPSS: 2.1% chance of exploitation in the next 30 days.

Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for unintended HTTP traffic on port 8445.

Affected products

  • Symantec Endpoint Protection Manager: up to and including 12.1.6

Published 2016-06-30. Last modified 2026-06-17.