CVE-2016-9097
A malicious administrator with read-only access can exploit this vulnerability to access management console functionality that requires read-write access privileges.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.35%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.8, ProxySG 6.5 prior 6.5.10.6, ProxySG 6.6 prior to 6.6.5.8, and ProxySG 6.7 prior to 6.7.1.2 management consoles do not, under certain circumstances, correctly authorize administrator users. A malicious administrator with read-only access can exploit this vulnerability to access management console functionality that requires read-write access privileges.
- CVSS 3.0
- 7.2 HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.35% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- broadcom/advanced secure gateway · broadcom/symantec proxysg
- Source
- secure@symantec.com
References
- http://www.securityfocus.com/bid/101530Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039701Third Party Advisory, VDB Entry
- https://www.symantec.com/security-center/network-protection-security-advisories/SA146Vendor Advisory
- http://www.securityfocus.com/bid/101530Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039701Third Party Advisory, VDB Entry
- https://www.symantec.com/security-center/network-protection-security-advisories/SA146Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.