Vulnerability CVE-2013-4673


Published: 2013-08-01

Description:
The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 does not properly implement RADIUS authentication, which allows remote attackers to execute arbitrary code by leveraging access to the login prompt.

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:A/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5.8/10
6.4/10
6.5/10
Exploit range
Attack complexity
Authentication
Adjacent network
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Symantec -> Web gateway 
Symantec -> Web gateway appliance 8450 
Symantec -> Web gateway appliance 8490 

 References:
http://osvdb.org/95702
http://www.securityfocus.com/bid/61105
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130725_00
https://exchange.xforce.ibmcloud.com/vulnerabilities/85990

Copyright 2024, cxsecurity.com

 

Back to Top