CVE Vulnerabilities

CVE-2016-2203

Published: Apr 22, 2016 | Modified: Jun 25, 2019
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discover an encrypted AD password by leveraging certain read privileges.

Affected Software

Name Vendor Start Version End Version
Messaging_gateway Symantec 10.6.0-patch3 (including) 10.6.0-patch3 (including)
Messaging_gateway Symantec 10.6.0-patch5 (including) 10.6.0-patch5 (including)
Messaging_gateway Symantec 10.6.0-patch7 (including) 10.6.0-patch7 (including)

References