Is Endpoint Protection Manager affected by CVE-2023-3823, CVE-2023-3824 and CVE-2023-3247?
search cancel

Is Endpoint Protection Manager affected by CVE-2023-3823, CVE-2023-3824 and CVE-2023-3247?

book

Article ID: 275508

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

You are inquiring to see if the Symantec Endpoint Protection Manager (SEPM) is affected by the PHP vulnerabilities reported through the following CVEs:
 

CVE-2023-3823

CVE-2023-3824

CVE-2023-3247

Environment

Symantec Endpoint Protection Manager

Resolution

 

The Symantec Endpoint Protection Manager is NOT affected by CVE-2023-3823, CVE-2023-3824 and CVE-2023-3247.

 

CVE-2023-3823: SOAP HTTP Digest Authentication is not used by SEPM PHP.
 

CVE-2023-3824: Even though the PHAR extension is in the loaded module list of SEPM PHP, it is not used and no Phar files are loaded in SEPM.

 

CVE-2023-3247: It's been analyzed before that SEPM PHP loads only trusted XML via calls such as loadXML, thus the exploit cannot be triggered.