CVE-2013-4671
Summary
| CVE | CVE-2013-4671 |
|---|---|
| State | PUBLISHED |
| Assigner | symantec |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-08-01 13:32:21 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-site request forgery (CSRF) vulnerability in the management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec | Web Gateway | 5.0 | All | All | All |
| Application | Symantec | Web Gateway | 5.0.1 | All | All | All |
| Application | Symantec | Web Gateway | 5.0.2 | All | All | All |
| Application | Symantec | Web Gateway | 5.0.3 | All | All | All |
| Application | Symantec | Web Gateway | 5.0.3.18 | All | All | All |
| Application | Symantec | Web Gateway | All | All | All | All |
| Hardware | Symantec | Web Gateway Appliance 8450 | - | All | All | All |
| Hardware | Symantec | Web Gateway Appliance 8490 | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Symantec Web Gateway XSS / CSRF / SQL Injection / Command Injection ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| osvdb.org/95699 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Symantec Web Gateway CVE-2013-4671 Cross Site Request Forgery Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Vulnerability Lab - SEC Consult | af854a3a-2127-422b-91ae-364da2661108 | www.sec-consult.com | |
| Security Advisories Relating to Symantec Products - Symantec Web Gateway Security Issues - 2013-07-25T11:42:30 PDT | Symantec | af854a3a-2127-422b-91ae-364da2661108 | www.symantec.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.