CVE-2016-2206

EUVD-2016-3290
The management console in Symantec Workspace Streaming (SWS) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 and Symantec Workspace Virtualization (SWV) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 allows remote authenticated users to read arbitrary files by modifying the file-download configuration file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.7 MEDIUM
ADJACENT_NETWORK
LOW
LOW
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
Affected Products (NVD)
VendorProductVersion
symantecworkspace_streaming
7.5.0
symantecworkspace_streaming
7.5.0:sp1
symantecworkspace_streaming
7.6.0
symantecworkspace_virtualization
7.5.0
symantecworkspace_virtualization
7.5.0:sp1
symantecworkspace_virtualization
7.6.0
𝑥
= Vulnerable software versions
Common Weakness Enumeration