Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.105620
Category:Web application abuses
Title:Symantec Messaging Gateway Multiple Vulnerabilities (SYM16-005)
Summary:Symantec Messaging Gateway is prone to multiple; vulnerabilities.
Description:Summary:
Symantec Messaging Gateway is prone to multiple
vulnerabilities.

Vulnerability Insight:
Symantec Messaging Gateway (SMG) Appliance management console
is susceptible to potential recovery of the AD password by any user with at least authorized read
access to the appliance. Also, an admin or support user could potentially escalate a
lower-privileged access to root on the appliance by escaping their terminal window to a
privileged shell.

Vulnerability Impact:
Successful exploitation could result in elevated access to the
SMG Appliance management console or to the network environment.

Affected Software/OS:
Symantec Messaging Gateway version 10.6.0-7 and prior.

Solution:
Update to version 10.6.1 or later.

CVSS Score:
6.5

CVSS Vector:
AV:L/AC:L/Au:M/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-2203
BugTraq ID: 86137
http://www.securityfocus.com/bid/86137
https://www.exploit-db.com/exploits/39715/
http://packetstormsecurity.com/files/136758/Symantec-Brightmail-10.6.0-7-LDAP-Credential-Grabber.html
http://www.securitytracker.com/id/1035609
Common Vulnerability Exposure (CVE) ID: CVE-2016-2204
BugTraq ID: 86138
http://www.securityfocus.com/bid/86138
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.