CVE-2012-3579

Symantec Messaging Gateway < 9.5.4 - Default SSH Credentials

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2012-3579. PoCs published by Metasploit, Stefan Viehbock, Ben Williams, sinn3r, including Metasploit module exploits/linux/ssh/symantec_smg_ssh.

AI-analyzed exploit summary This Metasploit module exploits a default credential vulnerability in Symantec Messaging Gateway 9.5, where the 'support' user has a known default password ('symantec'). It establishes an SSH connection and provides an interactive command shell.

Description

Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier for remote attackers to obtain privileged access via an SSH session.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/21136

This Metasploit module exploits a default credential vulnerability in Symantec Messaging Gateway 9.5, where the 'support' user has a known default password ('symantec'). It establishes an SSH connection and provides an interactive command shell.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Symantec Messaging Gateway 9.5
No auth needed
Prerequisites: SSH service exposed on port 22 · Default credentials not changed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Stefan Viehbock, Ben Williams, sinn3r · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/ssh/symantec_smg_ssh.rb

This Metasploit module exploits a default misconfiguration in Symantec Messaging Gateway 9.5, where the 'support' user has a known default password ('symantec'). It leverages SSH authentication to gain privileged remote access.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Symantec Messaging Gateway 9.5
No auth needed
Prerequisites: SSH service exposed on port 22 · Default credentials not changed
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4

Scores

EPSS 0.4021
EPSS Percentile 98.5%

Details

CWE
CWE-264
Status published
Products (5)
symantec/messaging_gateway 9.5
symantec/messaging_gateway 9.5.1
symantec/messaging_gateway 9.5.2
symantec/messaging_gateway 9.5.3
symantec/messaging_gateway < 9.5.4
Published Aug 29, 2012
Tracked Since Feb 18, 2026