7.2
CVSSv2

CVE-2013-4672

Published: 01/08/2013 Updated: 17/01/2014
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 4.1
VMScore: 641
Vector: AV:A/AC:L/Au:M/C:C/I:C/A:C

Vulnerability Summary

The management console on the Symantec Web Gateway (SWG) appliance prior to 5.1.1 has an incorrect sudoers file, which allows local users to bypass intended access restrictions via a command.

Vulnerable Product Search on Vulmon Subscribe to Product

symantec web gateway

symantec web gateway 5.0

symantec web gateway 5.0.1

symantec web gateway 5.0.2

symantec web gateway 5.0.3

symantec web gateway 5.0.3.18

symantec web gateway appliance 8450 -

symantec web gateway appliance 8490 -

Exploits

Symantec Web Gateway versions 510* and below suffer from cross site request forgery, cross site scripting, command injection, and remote SQL injection vulnerabilities ...