CVE-2016-10258
6.8MEDIUM
Key Information:
- Vendor
- Symantec Corporation
- Status
- Advanced Secure Gateway (asg)
- Proxysg
- Vendor
- CVE Published:
- 11 April 2018
Summary
Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator user into downloading and executing malicious code.
Affected Version(s)
Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.14
Advanced Secure Gateway (ASG) 6.7 prior to 6.7.3.1
ProxySG 6.5 prior to 6.5.10.8
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved