Show plain JSON{"id": "CVE-2019-12755", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 2.1, "accessVector": "LOCAL", "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "LOW", "obtainAllPrivilege": false, "exploitabilityScore": 3.9, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 5.5, "attackVector": "LOCAL", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 3.6, "exploitabilityScore": 1.8}]}, "published": "2019-09-17T16:15:10.827", "references": [{"url": "https://support.symantec.com/us/en/article.SYMSA1493.html", "tags": ["Vendor Advisory"], "source": "secure@symantec.com"}, {"url": "https://support.symantec.com/us/en/article.SYMSA1493.html", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}], "descriptions": [{"lang": "en", "value": "Norton Password Manager, prior to 6.5.0.2104, may be susceptible to an information disclosure issue, which is a type of vulnerability whereby there is an unintentional disclosure of information to an actor that is not explicitly authorized to have access to that information."}, {"lang": "es", "value": "Norton Password Manager, versiones anteriores a 6.5.0.2104, puede ser susceptible a un problema de divulgaci\u00f3n de informaci\u00f3n, que es un tipo de vulnerabilidad por la cual se presenta una divulgaci\u00f3n no intencional de informaci\u00f3n en un actor que no est\u00e1 expl\u00edcitamente autorizado para tener acceso a esa informaci\u00f3n."}], "lastModified": "2024-11-21T04:23:30.393", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:symantec:norton_password_manager:*:*:*:*:*:android:*:*", "vulnerable": true, "matchCriteriaId": "4EF3278A-7591-4F95-82B5-4676E4DE8C7B", "versionEndExcluding": "6.5.0.2104"}], "operator": "OR"}]}], "sourceIdentifier": "secure@symantec.com"}