CVE-2018-12242
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allow attackers to potentially circumvent security mechanisms currently in place and gain access to the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.95%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allow attackers to potentially circumvent security mechanisms currently in place and gain access to the system or network.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.95% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- symantec/messaging gateway
- Source
- secure@symantec.com
References
- http://www.securityfocus.com/bid/105329Third Party Advisory, VDB Entry
- https://support.symantec.com/en_US/article.SYMSA1461.htmlVendor Advisory
- http://www.securityfocus.com/bid/105329Third Party Advisory, VDB Entry
- https://support.symantec.com/en_US/article.SYMSA1461.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.