CVE-2020-12595

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/12/2020
Last modified:
14/12/2020

Description

An information disclosure flaw allows a malicious, authenticated, privileged web UI user to obtain a password for a remote SCP backup server that they might not otherwise be authorized to access. This affects SMG prior to 10.7.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:broadcom:symantec_messaging_gateway:*:*:*:*:*:*:*:* 10.7.4 (excluding)