CVE Vulnerabilities

CVE-2021-30648

Improper Authentication

Published: Jun 30, 2021 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthenticated attacker can execute arbitrary CLI commands, view/modify the appliance configuration and policy, and shutdown/restart the appliance.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Symantec_proxysgBroadcom6.5 (including)6.5.10.16 (excluding)
Symantec_proxysgBroadcom6.6 (including)6.6.5.19 (excluding)
Symantec_proxysgBroadcom6.7 (including)6.7.5.12 (excluding)
Symantec_proxysgBroadcom7.2 (including)7.2.7.2 (excluding)
Symantec_proxysgBroadcom7.3 (including)7.3.3.3 (excluding)

Potential Mitigations

References