CVE-2016-9097
7.2
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD
Description
The Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.8, ProxySG 6.5 prior 6.5.10.6, ProxySG 6.6 prior to 6.6.5.8, and ProxySG 6.7 prior to 6.7.1.2 management consoles do not, under certain circumstances, correctly authorize administrator users. A malicious administrator with read-only access can exploit this vulnerability to access management console functionality that requires read-write access privileges.
Affected (29)
Products: Broadcom: Advanced Secure Gateway, Symantec Proxysg
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.6.3 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.5.1 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.6.2.1 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.7.1.1 |
Related CWEs
References (6)
Source: secure@symantec.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.