20170817 CVE-2017-6327: Symantec Messaging Gateway <= 10.6.3-2 unauthenticated root RCEmailing list
http://seclists.org/fulldisclosure/2017/Aug/28 CVE-2017-6327
HIGHCISA KEV
Symantec Messaging Gateway Remote Code Execution Vulnerability
Record summary
CVE-2017-6327 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit. CISA lists CVE-2017-6327 in KEV.
Description
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. In this type of occurrence, after gaining access to the system, the attacker may attempt to elevate their privileges.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Nov 3, 2021 · CISA
- VulnCheck KEV
- Listed · Oct 20, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 7, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Symantec Messaging GatewayBrowse Symantec / Symantec Messaging Gateway | CISA | Version data not supplied | |
Messaging GatewayBrowse Symantec Corporation / Messaging Gateway | CVE List | All versions prior to version 10.6.3-267 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBSymantec Messaging Gateway 10.6.3-2 - Root Remote Command ExecutionExploitDB exploitby Philip PetterssonNot analyzed1 file
References
6100135vdb entry
http://www.securityfocus.com/bid/100135 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-6327 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6327 42519exploit
https://www.exploit-db.com/exploits/42519 symantec.comConfirmation
https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20170810_00