Local Access Bypass Issue in Symantec Web Gateway Appliance
CVE-2013-4672
Currently unrated
Key Information:
- Vendor
- Symantec
- Vendor
- CVE Published:
- 1 August 2013
Summary
The Symantec Web Gateway appliance prior to version 5.1.1 has a vulnerability within its management console due to an incorrectly configured sudoers file. This misconfiguration allows local users to circumvent intended access restrictions by executing commands that should otherwise be blocked. As a result, local threats can exploit this weakness to gain unauthorized access to system commands and functionalities.
References
Timeline
Vulnerability published
Vulnerability Reserved