CVE-2012-3579
Symantec Messaging Gateway < 9.5.4 - Default SSH Credentials
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2012-3579.
PoCs published by Metasploit, Stefan Viehbock, Ben Williams, sinn3r, including Metasploit module exploits/linux/ssh/symantec_smg_ssh.
AI-analyzed exploit summary This Metasploit module exploits a default credential vulnerability in Symantec Messaging Gateway 9.5, where the 'support' user has a known default password ('symantec'). It establishes an SSH connection and provides an interactive command shell.
Description
Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier for remote attackers to obtain privileged access via an SSH session.
Exploits (2)
This Metasploit module exploits a default credential vulnerability in Symantec Messaging Gateway 9.5, where the 'support' user has a known default password ('symantec'). It establishes an SSH connection and provides an interactive command shell.
This Metasploit module exploits a default misconfiguration in Symantec Messaging Gateway 9.5, where the 'support' user has a known default password ('symantec'). It leverages SSH authentication to gain privileged remote access.