Vulnerability record · CVE-2015-1486 · published 1 August 2015
CVE-2015-1486: Symantec Endpoint Protection Manager authentication bypass via password-reset action
Symantec · Endpoint Protection Manager
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication by sending a crafted password-reset action that triggers a new administrative session. Because the flaw grants administrative access without valid credentials, it exposes the central management plane that controls endpoint protection across the estate.
Description
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a crafted password-reset action that triggers a new administrative session.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
critical priorityUnauthenticated remote administrative access to a central endpoint security management console, with public exploit code and very high EPSS, makes this an urgent patching priority.
What it is
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication by sending a crafted password-reset action that triggers a new administrative session. Because the flaw grants administrative access without valid credentials, it exposes the central management plane that controls endpoint protection across the estate.
Impact
An unauthenticated remote attacker gains an administrative session on the SEPM console, giving control over endpoint security policy and managed clients. This can be used to weaken or disable protections across the organization.
Attack surface
Reachable over the network against the SEPM management console, per the AV:N vector. No authentication is required (Au:N), and the description indicates no user interaction beyond sending the crafted password-reset request.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.68339, 99.3rd percentile) and a public Exploit-DB entry (37812) exists, indicating exploit code is available and exploitation is plausible.
What to do
- Upgrade SEPM to 12.1-RU6-MP1 or later as the primary fix.
- Restrict network access to the SEPM management console to trusted administrative networks and hosts.
- Place the management console behind a firewall or VPN and avoid exposing it to untrusted networks.
- Monitor and audit SEPM administrative sessions for unexpected or anomalous logins.
- If immediate patching is not possible, isolate the console and apply compensating network controls.
Detection
- Review SEPM console and web server logs for password-reset requests that result in new administrative sessions without prior authentication.
- Alert on administrative session creation from unexpected source IPs or outside normal admin activity windows.
- Hunt for use of the public Exploit-DB PoC (37812) patterns in HTTP requests to the SEPM console.
- Correlate SEPM audit logs with network logs for unauthenticated access to management console endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-1486 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-1486), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.