6.1

CVE-2016-9099

Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 prior to 6.7.2.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6, and ProxySG 6.7 prior to 6.7.2.1 are susceptible to an open redirection vulnerability. A remote attacker can use a crafted management console URL in a phishing attack to redirect the target user to a malicious web site.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Broadcom ≫ Advanced Secure Gateway Version >= 6.7 < 6.7.2.1
Broadcom ≫ Symantec Proxysg Version >= 6.5 < 6.5.10.6
Broadcom ≫ Symantec Proxysg Version 6.6
Broadcom ≫ Symantec Proxysg Version >= 6.7 < 6.7.2.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.83% 0.76
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

http://www.securityfocus.com/bid/102455
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1040138
Third Party Advisory
VDB Entry
https://www.symantec.com/security-center/network-protection-security-advisories/SA155
Vendor Advisory