Reflected XSS Vulnerability in Symantec Advanced Secure Gateway and ProxySG
CVE-2016-10257
6.1MEDIUM
What is CVE-2016-10257?
The management console of Symantec's Advanced Secure Gateway (ASG) and ProxySG products is vulnerable to a reflected cross-site scripting (XSS) attack. An attacker can exploit this vulnerability by crafting a malicious URL that, when accessed, injects arbitrary JavaScript code into the web client application of the management console. This could facilitate phishing attacks and allow for the execution of harmful scripts in the context of authenticated user sessions. The affected versions include ASG 6.6, ASG 6.7 (prior to 6.7.2.1), ProxySG 6.5 (prior to 6.5.10.6), ProxySG 6.6, and ProxySG 6.7 (prior to 6.7.2.1).
Affected Version(s)
ASG 6.6
ASG 6.7 prior to 6.7.2.1
ProxySG 6.5 prior to 6.5.10.6
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved