CVE-2023-23958
Symantec Protection Engine vulnerability analysis and mitigation

Overview

Symantec Protection Engine (SPE), prior to version 9.1.0, contains a Hash Leak vulnerability identified as CVE-2023-23958. The vulnerability affects the legacy web console of SPE and was discovered by Michal Bogdanowicz and Lukasz Bialek from NORDEA BANK ABP. This security issue was disclosed in September 2023 and affects both Protection Engine for Cloud Services and Protection Engine for NAS products (Broadcom Advisory).

Technical details

The vulnerability is classified as medium severity with a CVSS v3.1 base score of 6.8 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N). The issue allows sensitive information to be exposed to actors who are not explicitly authorized to access that information. The vulnerability specifically affects the legacy web console component of the Symantec Protection Engine (NVD, Broadcom Advisory).

Impact

The primary impact of this vulnerability is the potential exposure of sensitive information to unauthorized actors. The CVSS scoring indicates high confidentiality impact (C:H) while integrity and availability are not affected (I:N/A:N), suggesting that the vulnerability primarily concerns data exposure rather than system manipulation or service disruption (Broadcom Advisory).

Mitigation and workarounds

Symantec has released version 9.1.0 of the Protection Engine to address this vulnerability. Additionally, several mitigation measures are recommended: use the new Symantec Protection Engine centralized console, restrict access to administrative systems to authorized privileged users, restrict remote access to trusted systems only, implement least privilege principles, keep systems updated with current patches, and deploy a multi-layered security approach including firewalls and intrusion detection systems (Broadcom Advisory).

Additional resources


SourceThis report was generated using AI

Related Symantec Protection Engine vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-23958MEDIUM6.5
  • Symantec Protection EngineSymantec Protection Engine
  • cpe:2.3:a:symantec:protection_engine
NoYesSep 27, 2023
CVE-2016-5310MEDIUM5.5
  • Symantec Endpoint ProtectionSymantec Endpoint Protection
  • cpe:2.3:a:symantec:protection_for_sharepoint_servers
NoYesApr 14, 2017
CVE-2016-5309MEDIUM5.5
  • Symantec Endpoint ProtectionSymantec Endpoint Protection
  • cpe:2.3:a:symantec:endpoint_protection:*:*:*:*:*:windows:*:*
NoYesApr 14, 2017
CVE-2016-5306MEDIUM5.3
  • Symantec Endpoint ProtectionSymantec Endpoint Protection
  • cpe:2.3:a:symantec:endpoint_protection_manager
NoNoJun 30, 2016
CVE-2016-5307MEDIUM4.3
  • Symantec Endpoint ProtectionSymantec Endpoint Protection
  • cpe:2.3:a:symantec:endpoint_protection_manager
NoNoJun 30, 2016

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management