Local Access Bypass Issue in Symantec Web Gateway Appliance
CVE-2013-4672

Currently unrated

Key Information:

Summary

The Symantec Web Gateway appliance prior to version 5.1.1 has a vulnerability within its management console due to an incorrectly configured sudoers file. This misconfiguration allows local users to circumvent intended access restrictions by executing commands that should otherwise be blocked. As a result, local threats can exploit this weakness to gain unauthorized access to system commands and functionalities.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.