CVE-2021-30648

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
30/06/2021
Last modified:
06/07/2021

Description

The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthenticated attacker can execute arbitrary CLI commands, view/modify the appliance configuration and policy, and shutdown/restart the appliance.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:broadcom:symantec_proxysg:*:*:*:*:*:*:*:* 6.5 (including) 6.5.10.16 (excluding)
cpe:2.3:a:broadcom:symantec_proxysg:*:*:*:*:*:*:*:* 6.6 (including) 6.6.5.19 (excluding)
cpe:2.3:a:broadcom:symantec_proxysg:*:*:*:*:*:*:*:* 6.7 (including) 6.7.5.12 (excluding)
cpe:2.3:a:broadcom:symantec_proxysg:*:*:*:*:*:*:*:* 7.2 (including) 7.2.7.2 (excluding)
cpe:2.3:a:broadcom:symantec_proxysg:*:*:*:*:*:*:*:* 7.3 (including) 7.3.3.3 (excluding)
cpe:2.3:o:broadcom:symantec_advanced_secure_gateway_s200-30_firmware:*:*:*:*:*:*:*:* 6.6 (including) 6.7.4.17 (excluding)
cpe:2.3:o:broadcom:symantec_advanced_secure_gateway_s200-30_firmware:*:*:*:*:*:*:*:* 6.7.5.0 (including) 6.7.5.12 (excluding)
cpe:2.3:o:broadcom:symantec_advanced_secure_gateway_s200-30_firmware:*:*:*:*:*:*:*:* 7.2 (including) 7.2.7.2 (excluding)
cpe:2.3:o:broadcom:symantec_advanced_secure_gateway_s200-30_firmware:*:*:*:*:*:*:*:* 7.3 (including) 7.3.3.3 (excluding)
cpe:2.3:h:broadcom:symantec_advanced_secure_gateway_s200-30:-:*:*:*:*:*:*:*
cpe:2.3:o:broadcom:symantec_advanced_secure_gateway_s200-40_firmware:*:*:*:*:*:*:*:* 6.6 (including) 6.7.4.17 (excluding)
cpe:2.3:o:broadcom:symantec_advanced_secure_gateway_s200-40_firmware:*:*:*:*:*:*:*:* 6.7.5.0 (including) 6.7.5.12 (excluding)
cpe:2.3:o:broadcom:symantec_advanced_secure_gateway_s200-40_firmware:*:*:*:*:*:*:*:* 7.2 (including) 7.2.7.2 (excluding)
cpe:2.3:o:broadcom:symantec_advanced_secure_gateway_s200-40_firmware:*:*:*:*:*:*:*:* 7.3 (including) 7.3.3.3 (excluding)
cpe:2.3:h:broadcom:symantec_advanced_secure_gateway_s200-40:-:*:*:*:*:*:*:*