Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-10257


The Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 (prior to 6.7.2.1), ProxySG 6.5 (prior to 6.5.10.6), ProxySG 6.6, and ProxySG 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A remote attacker can use a crafted management console URL in a phishing attack to inject arbitrary JavaScript code into the management console web client application. This is a separate vulnerability from CVE-2016-10256.


Published

2018-01-10T02:29:31.880

Last Modified

2024-11-21T02:43:40.397

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 6.1 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application broadcom advanced_secure_gateway < 6.7.2.1 Yes
Application broadcom advanced_secure_gateway 6.6 Yes
Application broadcom symantec_proxysg < 6.5.10.6 Yes
Application broadcom symantec_proxysg < 6.7.2.1 Yes
Application broadcom symantec_proxysg 6.6 Yes

References