Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator user into downloading and executing malicious code.
2018-04-11T14:29:00.250
2024-11-21T02:43:40.507
Modified
CVSSv3.0: 6.8 (MEDIUM)
AV:N/AC:M/Au:S/C:P/I:P/A:P
6.8
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | broadcom | advanced_secure_gateway | < 6.6.5.14 | Yes |
Application | broadcom | advanced_secure_gateway | < 6.7.3.1 | Yes |
Application | broadcom | symantec_proxysg | < 6.5.10.8 | Yes |
Application | broadcom | symantec_proxysg | < 6.6.5.14 | Yes |
Application | broadcom | symantec_proxysg | < 6.7.3.1 | Yes |