Symantec Corporation Vulnerabilities and Affected Products
Vulnerabilities associated with Symantec Advanced Secure Gateway (ASG).
Products
Clear product- ProxySG8 vulnerabilities
- Messaging Gateway6 vulnerabilities
- Symantec Endpoint Protection5 vulnerabilities
- Advanced Secure Gateway (ASG)4 vulnerabilities
- Norton App Lock4 vulnerabilities
- ASG3 vulnerabilities
- Symantec Endpoint Encryption3 vulnerabilities
- Endpoint Protection2 vulnerabilities
- Norton Family Android App2 vulnerabilities
- Norton Password Manager2 vulnerabilities
- Norton Security2 vulnerabilities
- Norton; Symantec Endpoint Protection (SEP); Symantec Endpoint Protection Small Business Edition (SEP SBE); Symantec Endpoint Protection Cloud (SEP Cloud)2 vulnerabilities
- Symantec Advanced Secure Gateway (ASG)2 vulnerabilities
- Symantec Encryption Desktop2 vulnerabilities
- Symantec Messaging Gateway2 vulnerabilities
- Symantec ProxySG2 vulnerabilities
- Symantec Reporter2 vulnerabilities
- Blue Coat ASG1 vulnerability
- Blue Coat CAS1 vulnerability
- Content Analysis (CA)1 vulnerability
- Ghost Solution Suite (GSS)1 vulnerability
- Industrial Control System Protection (ICSP)1 vulnerability
- IntelligenceCenter1 vulnerability
- Inventory Plugin for Symantec Management Agent1 vulnerability
- ITMS1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-18371MEDIUM | The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser. An information disclosure vulnerability in the WebFTP mode allows a malicious user to obtain plaintext authentication credentials for a remote FTP server from the ASG/ProxySG's web listing of the FTP server. Affected versions: ASG 6.6 and 6.7 prior to 6.7.4.2; ProxySG 6.5 prior to 6.5.10.15, 6.6, and 6.7 prior to 6.7.4.2. CWE-327Aug 29, 2019 | CVSS6.5v3.0 | EPSS0.589% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-18370MEDIUM | The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser. A stored cross-site scripting (XSS) vulnerability in the WebFTP mode allows a remote attacker to inject malicious JavaScript code in ASG/ProxySG's web listing of a remote FTP server. Exploiting the vulnerability requires the attacker to be able to upload crafted files to the remote FTP server. Affected versions: ASG 6.6 and 6.7 prior to 6.7.4.2; ProxySG… CWE-79Aug 29, 2019 | CVSS6.1v3.0 | EPSS0.772% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |