{ "id": "CVE-2017-15534", "sourceIdentifier": "secure@symantec.com", "published": "2018-03-26T16:29:00.223", "lastModified": "2019-10-03T00:03:26.223", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "The Norton App Lock prior to version 1.3.0.13 can be susceptible to an authentication bypass exploit. In this type of circumstance, the exploit can allow the user to kill the app to prevent it from locking the device, thereby allowing the individual to gain device access." }, { "lang": "es", "value": "Norton App Lock en versiones anteriores a la 1.3.0.13 puede ser vulnerable a un exploit de omisi\u00f3n de autenticaci\u00f3n En este caso espec\u00edfico, el exploit puede permitir al usuario forzar el cierre de la aplicaci\u00f3n para evitar que bloquee el dispositivo y, de ese modo, permitir al individuo obtener acceso a \u00e9l." } ], "metrics": { "cvssMetricV30": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseScore": 6.7, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 0.8, "impactScore": 5.9 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C", "accessVector": "LOCAL", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "availabilityImpact": "COMPLETE", "baseScore": 7.2 }, "baseSeverity": "HIGH", "exploitabilityScore": 3.9, "impactScore": 10.0, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-287" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:symantec:norton_app_lock:*:*:*:*:*:*:*:*", "versionEndExcluding": "1.3.0.13", "matchCriteriaId": "70C63C19-EAAB-4BC6-ACAD-B7D5F11663EE" } ] } ] } ], "references": [ { "url": "http://www.securityfocus.com/bid/103377", "source": "secure@symantec.com", "tags": [ "Third Party Advisory", "VDB Entry" ] }, { "url": "https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20180326_00", "source": "secure@symantec.com", "tags": [ "Mitigation", "Vendor Advisory" ] } ] }