CVE-2019-18375
MEDIUMBroadcom Advanced Secure Gateway and ProxySG 6.7.4-6.7.4.10 - Session Hijacking via Management Console
Title source: llmDescription
The ASG and ProxySG management consoles are susceptible to a session hijacking vulnerability. A remote attacker, with access to the appliance management interface, can hijack the session of a currently logged-in user and access the management console.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://support.broadcom.com/security-advisory/security-advisory-detail.html?notificationId=SYMSA1752
Scores
CVSS v3
6.5
EPSS
0.0022
EPSS Percentile
44.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Details
Status
published
Products (2)
broadcom/advanced_secure_gateway
6.7.4 - 6.7.4.10
broadcom/symantec_proxysg
6.7.4 - 6.7.4.10
Published
Apr 10, 2020
Tracked Since
Feb 18, 2026