CVE Vulnerabilities

CVE-2016-2203

Published: Apr 22, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discover an encrypted AD password by leveraging certain read privileges.

Affected Software

NameVendorStart VersionEnd Version
Messaging_gatewaySymantec10.6.0-patch3 (including)10.6.0-patch3 (including)
Messaging_gatewaySymantec10.6.0-patch5 (including)10.6.0-patch5 (including)
Messaging_gatewaySymantec10.6.0-patch7 (including)10.6.0-patch7 (including)

References