VulnerabilityModified
CVE-2012-2977
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwords via crafted input to an application script.
MEDIUM 5.0EPSS 2.78%
Does this matter?
Lower severity and a low EPSS score (2.78%). Track it; it rarely justifies an emergency change on its own.
Description
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwords via crafted input to an application script.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 2.78% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- symantec/web gateway
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/108471
- http://www.securityfocus.com/bid/54430
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120720_00
- http://www.kb.cert.org/vuls/id/108471
- http://www.securityfocus.com/bid/54430
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120720_00
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.