Symantec Corporation Vulnerabilities and Affected Products
Vulnerabilities associated with Advanced Secure Gateway (ASG).
Products
Clear product- ProxySG8 vulnerabilities
- Messaging Gateway6 vulnerabilities
- Symantec Endpoint Protection5 vulnerabilities
- Advanced Secure Gateway (ASG)4 vulnerabilities
- Norton App Lock4 vulnerabilities
- ASG3 vulnerabilities
- Symantec Endpoint Encryption3 vulnerabilities
- Endpoint Protection2 vulnerabilities
- Norton Family Android App2 vulnerabilities
- Norton Password Manager2 vulnerabilities
- Norton Security2 vulnerabilities
- Norton; Symantec Endpoint Protection (SEP); Symantec Endpoint Protection Small Business Edition (SEP SBE); Symantec Endpoint Protection Cloud (SEP Cloud)2 vulnerabilities
- Symantec Advanced Secure Gateway (ASG)2 vulnerabilities
- Symantec Encryption Desktop2 vulnerabilities
- Symantec Messaging Gateway2 vulnerabilities
- Symantec ProxySG2 vulnerabilities
- Symantec Reporter2 vulnerabilities
- Blue Coat ASG1 vulnerability
- Blue Coat CAS1 vulnerability
- Content Analysis (CA)1 vulnerability
- Ghost Solution Suite (GSS)1 vulnerability
- Industrial Control System Protection (ICSP)1 vulnerability
- IntelligenceCenter1 vulnerability
- Inventory Plugin for Symantec Management Agent1 vulnerability
- ITMS1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-5241CRITICAL | Symantec Advanced Secure Gateway (ASG) 6.6 and 6.7, and ProxySG 6.5, 6.6, and 6.7 are susceptible to a SAML authentication bypass vulnerability. The products can be configured with a SAML authentication realm to authenticate network users in intercepted proxy traffic. When parsing SAML responses, ASG and ProxySG incorrectly handle XML nodes with comments. A remote attacker can modify a valid SAML response without invalidating its cryptographic signature. This may allow the attacker to bypass use… May 29, 2018 | CVSS9.8v3.0 | EPSS4.62% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-10258MEDIUM | Symantec Advanced Secure Gateway (ASG) / ProxySG - Unrestricted File UploadUnrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator user into downloading and executing malicious code. CWE-434Apr 11, 2018 | CVSS6.8v3.0 | EPSS4.94% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-13677HIGH | Denial-of-service (DoS) vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A remote attacker can use crafted HTTP/HTTPS requests to cause denial-of-service through management console application crashes. Apr 11, 2018 | CVSS7.5v3.0 | EPSS5.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-13678MEDIUM | Stored XSS vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can inject arbitrary JavaScript code in the management console web client application. CWE-79Apr 11, 2018 | CVSS4.8v3.0 | EPSS1.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |