CVE-2016-10258

6.8MEDIUM

Key Information:

Vendor
Symantec Corporation
Status
Advanced Secure Gateway (asg)
Proxysg
Vendor
CVE Published:
11 April 2018

Summary

Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator user into downloading and executing malicious code.

Affected Version(s)

Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.14

Advanced Secure Gateway (ASG) 6.7 prior to 6.7.3.1

ProxySG 6.5 prior to 6.5.10.8

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.