CVE-2021-30648
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthenticated attacker can execute arbitrary CLI commands, view/modify the appliance configuration and policy, and shutdown/restart the appliance.
Affected (33)
Products: Broadcom: Symantec Proxysg, Symantec Advanced Secure Gateway S200 30 Firmware, Symantec Advanced Secure Gateway S200 40 Firmware, Symantec Advanced Secure Gateway S400 20 Firmware, Symantec Advanced Secure Gateway S400 30 Firmware, Symantec Advanced Secure Gateway S400 40 Firmware, Symantec Advanced Secure Gateway 500 10 Firmware, Symantec Advanced Secure Gateway S500 20 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.5 to 6.5.10.16 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.6 to 6.7.4.17 |
| Running on/with | Platform Versions |
|---|---|
Broadcom Symantec Advanced Secure Gateway S200 30 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.6 to 6.7.4.17 |
| Running on/with | Platform Versions |
|---|---|
Broadcom Symantec Advanced Secure Gateway S200 40 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.6 to 6.7.4.17 |
| Running on/with | Platform Versions |
|---|---|
Broadcom Symantec Advanced Secure Gateway S400 20 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.6 to 6.7.4.17 |
| Running on/with | Platform Versions |
|---|---|
Broadcom Symantec Advanced Secure Gateway S400 30 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.6 to 6.7.4.17 |
| Running on/with | Platform Versions |
|---|---|
Broadcom Symantec Advanced Secure Gateway S400 40 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.6 to 6.7.4.17 |
| Running on/with | Platform Versions |
|---|---|
Broadcom Symantec Advanced Secure Gateway 500 10 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.6 to 6.7.4.17 |
| Running on/with | Platform Versions |
|---|---|
Broadcom Symantec Advanced Secure Gateway S500 20 | All versions |
References (2)
Source: secure@symantec.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.