VulnerabilityModified
CVE-2012-3580
Symantec Messaging Gateway (SMG) before 10.0 allows remote authenticated users to modify the web application by leveraging access to the management interface.
HIGH 7.7EPSS 1.13%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Symantec Messaging Gateway (SMG) before 10.0 allows remote authenticated users to modify the web application by leveraging access to the management interface.
- CVSS 2.0
- 7.7 HIGHAV:A/AC:L/Au:S/C:C/I:C/A:C
- EPSS
- 1.13% probability · 64th percentile
- CISA KEV
- Not listed
- Affected
- symantec/messaging gateway
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/55141
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120827_00Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78032
- http://www.securityfocus.com/bid/55141
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120827_00Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78032
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.