CVE-2017-6327

HIGH KEV

Symantec Message Gateway < 10.6.3-267 - Command Injection

Title source: rule

Description

The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. In this type of occurrence, after gaining access to the system, the attacker may attempt to elevate their privileges.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Philip Pettersson · textwebappsjsp
https://www.exploit-db.com/exploits/42519

Scores

CVSS v3 8.8
EPSS 0.7679
EPSS Percentile 99.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2021-11-03
VulnCheck KEV 2020-10-20
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2017-15388
CWE
CWE-77
Status published
Products (2)
symantec/message_gateway < 10.6.3-267
Symantec Corporation/Messaging Gateway All versions prior to version 10.6.3-267
Published Aug 11, 2017
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026