Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-9099


Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 prior to 6.7.2.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6, and ProxySG 6.7 prior to 6.7.2.1 are susceptible to an open redirection vulnerability. A remote attacker can use a crafted management console URL in a phishing attack to redirect the target user to a malicious web site.


Published

2017-05-11T14:30:16.407

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 6.1 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-601

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application broadcom advanced_secure_gateway < 6.7.2.1 Yes
Application broadcom symantec_proxysg < 6.5.10.6 Yes
Application broadcom advanced_secure_gateway 6.6 Yes
Application broadcom symantec_proxysg 6.6 Yes
Application broadcom symantec_proxysg < 6.7.2.1 Yes

References