Symantec ProxySG and ASG Multiple Security Vulnerabilities
BID:103685
CVE-2016-10258 | CVE-2017-13677 | CVE-2017-13678 |Info
Symantec ProxySG and ASG Multiple Security Vulnerabilities
| Bugtraq ID: | 103685 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-13678 CVE-2017-13677 CVE-2016-10258 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2018 12:00AM |
| Updated: | Apr 10 2018 12:00AM |
| Credit: | Robert Jaroszuk @ RBS Security, Jakub Palaczynski and Pawel Bartunek. |
| Vulnerable: |
Symantec Proxysg 6.7.2.1 Symantec Proxysg 6.6.5.13 Symantec Proxysg 6.5.10.6 Symantec Advanced Secure Gateway 6.7.2.1 Symantec Advanced Secure Gateway 6.6.5.13 Bluecoat Proxysg 6.7 Bluecoat Proxysg 6.6 Bluecoat Proxysg 6.5 Bluecoat Advanced Secure Gateway 6.7 Bluecoat Advanced Secure Gateway 6.6.5.4 Bluecoat Advanced Secure Gateway 6.6 |
| Not Vulnerable: |
Symantec Proxysg 6.7.4.107 Symantec Proxysg 6.7.3.1 Symantec Proxysg 6.6.5.14 Symantec Proxysg 6.5.10.8 Symantec Advanced Secure Gateway 6.7.4.107 Symantec Advanced Secure Gateway 6.7.3.1 Symantec Advanced Secure Gateway 6.6.5.14 |
Discussion
Symantec ProxySG and ASG Multiple Security Vulnerabilities
Symantec ProxySG and ASG are prone to multiple security vulnerabilities.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user, to crash an application, resulting in a denial-of-service condition or to upload arbitrary files to the affected application; this can result in arbitrary code execution within the context of the vulnerable application.
Symantec ProxySG and ASG are prone to multiple security vulnerabilities.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user, to crash an application, resulting in a denial-of-service condition or to upload arbitrary files to the affected application; this can result in arbitrary code execution within the context of the vulnerable application.
Exploit / POC
Symantec ProxySG and ASG Multiple Security Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Symantec ProxySG and ASG Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Symantec ProxySG and ASG Multiple Security Vulnerabilities
References:
References:
- Symantec Homepage (Symantec)
- SA162: Multiple ASG and ProxySG Vulnerabilities (Symantec)