CVE-2017-15531: Symantec Reporter

Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.

Symantec Reporter 9.5 prior to 9.5.4.1 and 10.1 prior to 10.1.5.5 does not restrict excessive authentication attempts for management interface users. A remote attacker can use brute force search to guess a user password and gain access to Reporter.

Affected products

  • Symantec Reporter: from 9.5, before 9.5.4.1 (fixed in 9.5.4.1); version 10.1 only

Published 2018-01-23. Last modified 2026-06-17.