Symantec Corporation Vulnerabilities and Affected Products
Vulnerabilities associated with Symantec Messaging Gateway.
Products
Clear product- ProxySG8 vulnerabilities
- Messaging Gateway6 vulnerabilities
- Symantec Endpoint Protection5 vulnerabilities
- Advanced Secure Gateway (ASG)4 vulnerabilities
- Norton App Lock4 vulnerabilities
- ASG3 vulnerabilities
- Symantec Endpoint Encryption3 vulnerabilities
- Endpoint Protection2 vulnerabilities
- Norton Family Android App2 vulnerabilities
- Norton Password Manager2 vulnerabilities
- Norton Security2 vulnerabilities
- Norton; Symantec Endpoint Protection (SEP); Symantec Endpoint Protection Small Business Edition (SEP SBE); Symantec Endpoint Protection Cloud (SEP Cloud)2 vulnerabilities
- Symantec Advanced Secure Gateway (ASG)2 vulnerabilities
- Symantec Encryption Desktop2 vulnerabilities
- Symantec Messaging Gateway2 vulnerabilities
- Symantec ProxySG2 vulnerabilities
- Symantec Reporter2 vulnerabilities
- Blue Coat ASG1 vulnerability
- Blue Coat CAS1 vulnerability
- Content Analysis (CA)1 vulnerability
- Ghost Solution Suite (GSS)1 vulnerability
- Industrial Control System Protection (ICSP)1 vulnerability
- IntelligenceCenter1 vulnerability
- Inventory Plugin for Symantec Management Agent1 vulnerability
- ITMS1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-12243HIGH | The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack uses file URI schemes or relative paths in the system identifier to access files that should not normally be accessible. CWE-611Sep 19, 2018 | CVSS8.8v3.0 | EPSS0.767% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-12242CRITICAL | The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allow attackers to potentially circumvent security mechanisms currently in place and gain access to the system or network. CWE-287Sep 19, 2018 | CVSS9.8v3.0 | EPSS2.95% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |