VulnerabilityModified
CVE-2013-4673
The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 does not properly implement RADIUS authentication, which allows remote attackers to execute arbitrary code by leveraging access to the login prompt.
MEDIUM 5.8EPSS 1.29%
Does this matter?
Lower severity and a low EPSS score (1.29%). Track it; it rarely justifies an emergency change on its own.
Description
The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 does not properly implement RADIUS authentication, which allows remote attackers to execute arbitrary code by leveraging access to the login prompt.
- CVSS 2.0
- 5.8 MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.29% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- symantec/web gateway · symantec/web gateway appliance 8450 · symantec/web gateway appliance 8490
- Source
- secure@symantec.com
References
- http://osvdb.org/95702
- http://www.securityfocus.com/bid/61105
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130725_00Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85990
- http://osvdb.org/95702
- http://www.securityfocus.com/bid/61105
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130725_00Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85990
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.