CVE-2016-9100
Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.13, ASG 6.7 prior to 6.7.3.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6 prior to 6.6.5.13, and ProxySG 6.7 prior to 6.7.3.1 are susceptible to an information disclosure vulnerability.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.43%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.13, ASG 6.7 prior to 6.7.3.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6 prior to 6.6.5.13, and ProxySG 6.7 prior to 6.7.3.1 are susceptible to an information disclosure vulnerability. An attacker with local access to the client host of an authenticated administrator user can, under certain circumstances, obtain sensitive authentication credential information.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- broadcom/advanced secure gateway · broadcom/symantec proxysg
- Source
- secure@symantec.com
References
- http://www.securityfocus.com/bid/102454Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040138Third Party Advisory, VDB Entry
- https://www.symantec.com/security-center/network-protection-security-advisories/SA155Vendor Advisory
- http://www.securityfocus.com/bid/102454Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040138Third Party Advisory, VDB Entry
- https://www.symantec.com/security-center/network-protection-security-advisories/SA155Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.