CVE Vulnerabilities

CVE-2016-9097

Published: May 11, 2017 | Modified: Jul 08, 2021
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
8 HIGH
AV:N/AC:L/Au:S/C:P/I:P/A:C
RedHat/V2
RedHat/V3
Ubuntu

The Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.8, ProxySG 6.5 prior 6.5.10.6, ProxySG 6.6 prior to 6.6.5.8, and ProxySG 6.7 prior to 6.7.1.2 management consoles do not, under certain circumstances, correctly authorize administrator users. A malicious administrator with read-only access can exploit this vulnerability to access management console functionality that requires read-write access privileges.

Affected Software

Name Vendor Start Version End Version
Advanced_secure_gateway Broadcom 6.6 (including) 6.6 (including)
Advanced_secure_gateway Broadcom 6.6.3 (including) 6.6.3 (including)
Advanced_secure_gateway Broadcom 6.6.4 (including) 6.6.4 (including)
Advanced_secure_gateway Broadcom 6.6.4.3 (including) 6.6.4.3 (including)
Advanced_secure_gateway Broadcom 6.6.5.1 (including) 6.6.5.1 (including)

References