RSS   Vulnerabilities for 'Advanced secure gateway'   RSS

2020-04-10
 
CVE-2019-18375

NVD-CWE-noinfo
 

 
The ASG and ProxySG management consoles are susceptible to a session hijacking vulnerability. A remote attacker, with access to the appliance management interface, can hijack the session of a currently logged-in user and access the management console.

 
2019-08-30
 
CVE-2018-18371

CWE-200
 

 
The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser. An information disclosure vulnerability in the WebFTP mode allows a malicious user to obtain plaintext authentication credentials for a remote FTP server from the ASG/ProxySG's web listing of the FTP server. Affected versions: ASG 6.6 and 6.7 prior to 6.7.4.2; ProxySG 6.5 prior to 6.5.10.15, 6.6, and 6.7 prior to 6.7.4.2.

 
 
CVE-2018-18370

CWE-79
 

 
The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser. A stored cross-site scripting (XSS) vulnerability in the WebFTP mode allows a remote attacker to inject malicious JavaScript code in ASG/ProxySG's web listing of a remote FTP server. Exploiting the vulnerability requires the attacker to be able to upload crafted files to the remote FTP server. Affected versions: ASG 6.6 and 6.7 prior to 6.7.4.2; ProxySG 6.5 prior to 6.5.10.15, 6.6, and 6.7 prior to 6.7.4.2.

 
2018-05-29
 
CVE-2018-5241

CWE-noinfo
 

 
Symantec Advanced Secure Gateway (ASG) 6.6 and 6.7, and ProxySG 6.5, 6.6, and 6.7 are susceptible to a SAML authentication bypass vulnerability. The products can be configured with a SAML authentication realm to authenticate network users in intercepted proxy traffic. When parsing SAML responses, ASG and ProxySG incorrectly handle XML nodes with comments. A remote attacker can modify a valid SAML response without invalidating its cryptographic signature. This may allow the attacker to bypass user authentication security controls in ASG and ProxySG. This vulnerability only affects authentication of network users in intercepted traffic. It does not affect administrator user authentication for the ASG and ProxySG management consoles.

 
2018-04-11
 
CVE-2017-13677

CWE-noinfo
 

 
Denial-of-service (DoS) vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A remote attacker can use crafted HTTP/HTTPS requests to cause denial-of-service through management console application crashes.

 
2018-01-09
 
CVE-2016-10257

CWE-79
 

 
The Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 (prior to 6.7.2.1), ProxySG 6.5 (prior to 6.5.10.6), ProxySG 6.6, and ProxySG 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A remote attacker can use a crafted management console URL in a phishing attack to inject arbitrary JavaScript code into the management console web client application. This is a separate vulnerability from CVE-2016-10256.

 
2017-05-11
 
CVE-2016-9099

CWE-601
 

 
Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 prior to 6.7.2.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6, and ProxySG 6.7 prior to 6.7.2.1 are susceptible to an open redirection vulnerability. A remote attacker can use a crafted management console URL in a phishing attack to redirect the target user to a malicious web site.

 
 
CVE-2016-9097

 

 
The Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.8, ProxySG 6.5 prior 6.5.10.6, ProxySG 6.6 prior to 6.6.5.8, and ProxySG 6.7 prior to 6.7.1.2 management consoles do not, under certain circumstances, correctly authorize administrator users. A malicious administrator with read-only access can exploit this vulnerability to access management console functionality that requires read-write access privileges.

 

 >>> Vendor: Symantec 240 Products
Mail-gear
Norton antivirus
Pcanywhere
Norton utilities
I-gear
Raptor firewall
Liveupdate
Norton ghost
Enterprise firewall
Velociraptor
Gateway security
Norton internet security
Norton personal firewall
Firewall vpn appliance 100
Firewall vpn appliance 200
Firewall vpn appliance 200r
JAVA
Sygate personal firewall
Security check
Norton system works
Windows liveupdate
VXFS
Clientless vpn gateway 4400
Gateway security 5400
Antivirus scan engine
Norton antispam
Gateway security 5300
Client firewall
Client security
Brightmail antispam
Nexland isb soho firewall appliance
Nexland pro100 firewall appliance
Nexland pro400 firewall appliance
Nexland pro800 firewall appliance
Nexland pro800turbo firewall appliance
Nexland wavebase firewall appliance
Gateway security 320
Gateway security 360
Gateway security 360r
On command ccm
On icommand
Security check virus detection
Powerquest deploycenter
Web security
Mail security
Sav filter domino nt ports
Sav filter for domino nt
Gateway security 460
Symav filter domino nt
Antivirus scan engine for network attached storage
Discovery
On command discovery
Gateway security 300
Gateway security 400
Gateway security 5000 series
Gateway security 5100
Gateway security 5310
Sygate management server
Ghost solutions suite
Security information manager
On-demand agent
On-demand protection
Enterprise security manager
Host ids
Veritas netbackup client
Veritas netbackup enterprise server
Veritas netbackup server
Naveng driver
Navex15 driver
Sygate network access control
Automated support assistant
Livestate agent for windows
Symantec antivirus filtering +for domino
Mail security 8820 appliance
Veritas volume replicator
Antivirus
Norton 360
Veritas storage foundation
Backupexec system recovery
Livestate recovery
Norton save and recovery
Reporting server
Veritas backup exec
Altiris deployment solution
Mail security appliance
Backup exec for windows server
Scan engine
Symantec antivirus clearswift
Symantec antivirus filtering domino mpe
Symantec antivirus messaging
Symantec antivirus microsoft sharepoint
Symantec antivirus ms isa
Symantec antivirus network attached storage
Symantec antivirus scan engine
Symantec antivirus scan engine caching
Symantec mail security exchange
Symantec antivirus scan engine clearswift
Symantec antivirus scan engine for microsoft sharepoint
Symantec antivirus scan engine for ms isa
Symantec antivirus scan engine messaging
See all Products for Vendor Symantec


Copyright 2021, cxsecurity.com

 

Back to Top