Symantec Web Gateway CVE-2012-2957 Local File Manipulation Authentication Bypass Vulnerability
BID:54429
Info
Symantec Web Gateway CVE-2012-2957 Local File Manipulation Authentication Bypass Vulnerability
| Bugtraq ID: | 54429 |
| Class: | Design Error |
| CVE: |
CVE-2012-2957 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 20 2012 12:00AM |
| Updated: | Jul 24 2012 05:00AM |
| Credit: | Offensive Security |
| Vulnerable: |
Symantec Web Gateway 5.0.3 Symantec Web Gateway 5.0.1 |
| Not Vulnerable: | |
Discussion
Symantec Web Gateway CVE-2012-2957 Local File Manipulation Authentication Bypass Vulnerability
Symantec Web Gateway is prone to a local authentication-bypass vulnerability
A local attacker can exploit this issue by manipulating certain local files to bypass authentication and gain unauthorized privileged access to the application. Successful exploits may lead to other attacks.
Symantec Web Gateway versions 5.0.x.x are vulnerable.
Symantec Web Gateway is prone to a local authentication-bypass vulnerability
A local attacker can exploit this issue by manipulating certain local files to bypass authentication and gain unauthorized privileged access to the application. Successful exploits may lead to other attacks.
Symantec Web Gateway versions 5.0.x.x are vulnerable.
Exploit / POC
Symantec Web Gateway CVE-2012-2957 Local File Manipulation Authentication Bypass Vulnerability
An attacker can carry out this attack by gaining local interactive access to a vulnerable computer.
An attacker can carry out this attack by gaining local interactive access to a vulnerable computer.
Solution / Fix
Symantec Web Gateway CVE-2012-2957 Local File Manipulation Authentication Bypass Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Symantec Web Gateway CVE-2012-2957 Local File Manipulation Authentication Bypass Vulnerability
References:
References:
- Symantec Web Gateway (Symantec)