CVE-2021-30648
- EPSS 0.49%
- Published 30.06.2021 11:15:08
- Last modified 21.11.2024 06:04:21
The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthenticated attacker can execute arbitrary CLI commands, view/modify the appliance configuration and poli...
CVE-2019-18375
- EPSS 0.22%
- Published 10.04.2020 00:15:11
- Last modified 21.11.2024 04:33:09
The ASG and ProxySG management consoles are susceptible to a session hijacking vulnerability. A remote attacker, with access to the appliance management interface, can hijack the session of a currently logged-in user and access the management console...
CVE-2018-18370
- EPSS 0.25%
- Published 30.08.2019 09:15:16
- Last modified 21.11.2024 03:55:48
The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser. A stored cross-site scripting (XSS) vulnerability in the WebFTP mode allows a remote attacker to inject m...
CVE-2018-18371
- EPSS 0.27%
- Published 30.08.2019 09:15:16
- Last modified 21.11.2024 03:55:48
The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser. An information disclosure vulnerability in the WebFTP mode allows a malicious user to obtain plaintext au...
CVE-2018-5241
- EPSS 9.75%
- Published 29.05.2018 13:29:00
- Last modified 21.11.2024 04:08:24
Symantec Advanced Secure Gateway (ASG) 6.6 and 6.7, and ProxySG 6.5, 6.6, and 6.7 are susceptible to a SAML authentication bypass vulnerability. The products can be configured with a SAML authentication realm to authenticate network users in intercep...
CVE-2016-10258
- EPSS 10.95%
- Published 11.04.2018 14:29:00
- Last modified 21.11.2024 02:43:40
Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator u...
CVE-2017-13677
- EPSS 7.19%
- Published 11.04.2018 14:29:00
- Last modified 21.11.2024 03:11:24
Denial-of-service (DoS) vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A remote attacker can use crafted HTTP/HTTPS requests to cause denial-of-service through management console application crashes.
CVE-2017-13678
- EPSS 0.31%
- Published 11.04.2018 14:29:00
- Last modified 21.11.2024 03:11:24
Stored XSS vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can inject arbitrary JavaScript code in the management console web client application.
CVE-2016-10256
- EPSS 0.38%
- Published 10.01.2018 02:29:31
- Last modified 21.11.2024 02:43:40
The Symantec ProxySG 6.5 (prior to 6.5.10.6), 6.6, and 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A remote attacker can use a crafted management console URL in a phishing attack to inject arbitrary Java...
CVE-2016-10257
- EPSS 0.38%
- Published 10.01.2018 02:29:31
- Last modified 21.11.2024 02:43:40
The Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 (prior to 6.7.2.1), ProxySG 6.5 (prior to 6.5.10.6), ProxySG 6.6, and ProxySG 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A remote attacker can use...