VulnerabilityModified
CVE-2016-9091
Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susceptible to an OS command injection vulnerability.
HIGH 7.2EPSS 10.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.1%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susceptible to an OS command injection vulnerability. An authenticated malicious administrator can execute arbitrary OS commands with elevated system privileges.
- CVSS 3.0
- 7.2 HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 10.13% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- bluecoat/advanced secure gateway · bluecoat/content analysis system software
- Source
- secure@symantec.com
References
- http://www.securityfocus.com/bid/97372Third Party Advisory, VDB Entry
- https://bto.bluecoat.com/security-advisory/sa138Mitigation, Vendor Advisory
- https://www.exploit-db.com/exploits/41785/
- https://www.exploit-db.com/exploits/41786/
- http://www.securityfocus.com/bid/97372Third Party Advisory, VDB Entry
- https://bto.bluecoat.com/security-advisory/sa138Mitigation, Vendor Advisory
- https://www.exploit-db.com/exploits/41785/
- https://www.exploit-db.com/exploits/41786/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.