CVE Vulnerabilities

CVE-2016-9097

Published: May 11, 2017 | Modified: Apr 20, 2025
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
8 HIGH
AV:N/AC:L/Au:S/C:P/I:P/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.8, ProxySG 6.5 prior 6.5.10.6, ProxySG 6.6 prior to 6.6.5.8, and ProxySG 6.7 prior to 6.7.1.2 management consoles do not, under certain circumstances, correctly authorize administrator users. A malicious administrator with read-only access can exploit this vulnerability to access management console functionality that requires read-write access privileges.

Affected Software

NameVendorStart VersionEnd Version
Advanced_secure_gatewayBroadcom6.6 (including)6.6 (including)
Advanced_secure_gatewayBroadcom6.6.3 (including)6.6.3 (including)
Advanced_secure_gatewayBroadcom6.6.4 (including)6.6.4 (including)
Advanced_secure_gatewayBroadcom6.6.4.3 (including)6.6.4.3 (including)
Advanced_secure_gatewayBroadcom6.6.5.1 (including)6.6.5.1 (including)

References