7.8
CVE-2016-2203
- EPSS 7.06%
- Veröffentlicht 22.04.2016 18:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discover an encrypted AD password by leveraging certain read privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Symantec ≫ Messaging Gateway Version 10.6.0 Update patch3
Symantec ≫ Messaging Gateway Version 10.6.0 Update patch5
Symantec ≫ Messaging Gateway Version 10.6.0 Update patch7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 7.06% | 0.934 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
http://packetstormsecurity.com/files/136758/Symantec-Brightmail-10.6.0-7-LDAP-Credential-Grabber.html
http://www.securityfocus.com/bid/86137
http://www.securitytracker.com/id/1035609
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160418_00
https://www.exploit-db.com/exploits/39715/