Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-9100


Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.13, ASG 6.7 prior to 6.7.3.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6 prior to 6.6.5.13, and ProxySG 6.7 prior to 6.7.3.1 are susceptible to an information disclosure vulnerability. An attacker with local access to the client host of an authenticated administrator user can, under certain circumstances, obtain sensitive authentication credential information.


Published

2017-05-11T14:30:16.437

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-255

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application broadcom advanced_secure_gateway < 6.6.5.13 Yes
Application broadcom advanced_secure_gateway < 6.7.3.1 Yes
Application broadcom symantec_proxysg < 6.5.10.6 Yes
Application broadcom symantec_proxysg < 6.6.5.13 Yes
Application broadcom symantec_proxysg < 6.7.3.1 Yes

References