CVE-2013-4673
Summary
| CVE | CVE-2013-4673 |
|---|---|
| State | PUBLISHED |
| Assigner | symantec |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-08-01 13:32:21 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 does not properly implement RADIUS authentication, which allows remote attackers to execute arbitrary code by leveraging access to the login prompt. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
AdjacentAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:A/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec | Web Gateway | 5.0 | All | All | All |
| Application | Symantec | Web Gateway | 5.0.1 | All | All | All |
| Application | Symantec | Web Gateway | 5.0.2 | All | All | All |
| Application | Symantec | Web Gateway | 5.0.3 | All | All | All |
| Application | Symantec | Web Gateway | 5.0.3.18 | All | All | All |
| Application | Symantec | Web Gateway | All | All | All | All |
| Hardware | Symantec | Web Gateway Appliance 8450 | - | All | All | All |
| Hardware | Symantec | Web Gateway Appliance 8490 | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Security Advisories Relating to Symantec Products - Symantec Web Gateway Security Issues - 2013-07-25T11:42:30 PDT | Symantec | af854a3a-2127-422b-91ae-364da2661108 | www.symantec.com | Vendor Advisory |
| Symantec Web Gateway CVE-2013-4673 Remote Command Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| osvdb.org/95702 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.