{ "id": "CVE-2018-18363", "sourceIdentifier": "secure@symantec.com", "published": "2019-01-24T20:29:00.280", "lastModified": "2019-10-03T00:03:26.223", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "Norton App Lock prior to 1.4.0.445 can be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking the device, thereby allowing the individual to gain device access." }, { "lang": "es", "value": "Norton App Lock, en versiones anteriores a la 1.4.0.445, puede ser susceptible a un exploit de omisi\u00f3n. En este tipo de circunstancia, el exploit puede permitir que el usuario omita la aplicaci\u00f3n para evitar que bloquee el dispositivo, permitiendo que esa persona obtenga acceso al dispositivo." } ], "metrics": { "cvssMetricV30": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.0", "vectorString": "CVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "attackVector": "PHYSICAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseScore": 6.2, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 0.3, "impactScore": 5.9 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C", "accessVector": "LOCAL", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "availabilityImpact": "COMPLETE", "baseScore": 7.2 }, "baseSeverity": "HIGH", "exploitabilityScore": 3.9, "impactScore": 10.0, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-noinfo" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:symantec:norton_app_lock:*:*:*:*:*:*:*:*", "versionEndExcluding": "1.4.0.445", "matchCriteriaId": "C21AA844-D506-4D03-9B60-5693186164AF" } ] } ] } ], "references": [ { "url": "http://www.securityfocus.com/bid/106450", "source": "secure@symantec.com", "tags": [ "VDB Entry", "Third Party Advisory" ] }, { "url": "https://support.symantec.com/en_US/article.SYMSA1473.html", "source": "secure@symantec.com", "tags": [ "Mitigation", "Vendor Advisory" ] } ] }