Symantec Corporation Vulnerabilities and Affected Products
Vulnerabilities associated with Messaging Gateway.
Products
Clear product- ProxySG8 vulnerabilities
- Messaging Gateway6 vulnerabilities
- Symantec Endpoint Protection5 vulnerabilities
- Advanced Secure Gateway (ASG)4 vulnerabilities
- Norton App Lock4 vulnerabilities
- ASG3 vulnerabilities
- Symantec Endpoint Encryption3 vulnerabilities
- Endpoint Protection2 vulnerabilities
- Norton Family Android App2 vulnerabilities
- Norton Password Manager2 vulnerabilities
- Norton Security2 vulnerabilities
- Norton; Symantec Endpoint Protection (SEP); Symantec Endpoint Protection Small Business Edition (SEP SBE); Symantec Endpoint Protection Cloud (SEP Cloud)2 vulnerabilities
- Symantec Advanced Secure Gateway (ASG)2 vulnerabilities
- Symantec Encryption Desktop2 vulnerabilities
- Symantec Messaging Gateway2 vulnerabilities
- Symantec ProxySG2 vulnerabilities
- Symantec Reporter2 vulnerabilities
- Blue Coat ASG1 vulnerability
- Blue Coat CAS1 vulnerability
- Content Analysis (CA)1 vulnerability
- Ghost Solution Suite (GSS)1 vulnerability
- Industrial Control System Protection (ICSP)1 vulnerability
- IntelligenceCenter1 vulnerability
- Inventory Plugin for Symantec Management Agent1 vulnerability
- ITMS1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2017-15532MEDIUM | Prior to 10.6.4, Symantec Messaging Gateway may be susceptible to a path traversal attack (also known as directory traversal). These types of attacks aim to access files and directories that are stored outside the web root folder. By manipulating variables, it may be possible to access arbitrary files and directories stored on the file system including application source code or configuration and critical system files. CWE-22Dec 20, 2017 | CVSS5.7v3.0 | EPSS1.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-6327HIGH | Symantec Messaging Gateway Remote Code Execution VulnerabilityThe Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. In this type of occurrence, after gaining access to the system, the attacker may attempt to elevate their privileges. | CVSS8.8v3.1 | EPSS35.3% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-6328HIGH | Symantec Messaging Gateway < 10.6.3-267 - Cross-Site Request ForgeryThe Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbreviated as CSRF or XSRF), which is a type of malicious exploit of a website where unauthorized commands are transmitted from a user that the web application trusts. A CSRF attack attempts to exploit the trust that a specific website has in a user's browser. CWE-352Aug 11, 2017 | CVSS8.8v3.0 | EPSS2.14% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-6326CRITICAL | Symantec Messaging Gateway 10.6.2-7 - Remote Code Execution (Metasploit)The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. Jun 26, 2017 | CVSS10.0v3.0 | EPSS72.8% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-6325MEDIUM | The Symantec Messaging Gateway can encounter a file inclusion vulnerability, which is a type of vulnerability that is most commonly found to affect web applications that rely on a scripting run time. This issue is caused when an application builds a path to executable code using an attacker-controlled variable in a way that allows the attacker to control which file is executed at run time. This file inclusion vulnerability subverts how an application loads code for execution. Successful exploita… CWE-94Jun 26, 2017 | CVSS6.6v3.0 | EPSS2.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-6324HIGH | The Symantec Messaging Gateway, when processing a specific email attachment, can allow a malformed or corrupted Word file with a potentially malicious macro through despite the administrator having the 'disarm' functionality enabled. This constitutes a 'bypass' of the disarm functionality resident to the application. Jun 26, 2017 | CVSS7.3v3.0 | EPSS1.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |