CVE-2017-13678

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
11/04/2018
Last modified:
08/07/2021

Description

Stored XSS vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can inject arbitrary JavaScript code in the management console web client application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:broadcom:advanced_secure_gateway:*:*:*:*:*:*:*:* 6.6 (including) 6.6.5.14 (excluding)
cpe:2.3:a:broadcom:advanced_secure_gateway:*:*:*:*:*:*:*:* 6.7.3 (including) 6.7.3.7 (excluding)
cpe:2.3:a:broadcom:advanced_secure_gateway:*:*:*:*:*:*:*:* 6.7.4 (including) 6.7.4.107 (excluding)
cpe:2.3:a:broadcom:symantec_proxysg:*:*:*:*:*:*:*:* 6.5 (including) 6.5.10.8 (excluding)
cpe:2.3:a:broadcom:symantec_proxysg:*:*:*:*:*:*:*:* 6.6 (including) 6.6.5.14 (excluding)
cpe:2.3:a:broadcom:symantec_proxysg:*:*:*:*:*:*:*:* 6.7.3 (including) 6.7.3.7 (excluding)
cpe:2.3:a:broadcom:symantec_proxysg:*:*:*:*:*:*:*:* 6.7.4 (including) 6.7.4.107 (excluding)