Broadcom Symantec Messaging Gateway
By the Year
In 2024 there have been 2 vulnerabilities in Broadcom Symantec Messaging Gateway with an average score of 9.8 out of ten. Symantec Messaging Gateway did not have any published security vulnerabilities last year. That is, 2 more vulnerabilities have already been reported in 2024 as compared to last year.
Year | Vulnerabilities | Average Score |
---|---|---|
2024 | 2 | 9.80 |
2023 | 0 | 0.00 |
2022 | 1 | 4.90 |
2021 | 0 | 0.00 |
2020 | 2 | 6.05 |
2019 | 0 | 0.00 |
2018 | 0 | 0.00 |
It may take a day or so for new Symantec Messaging Gateway vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Broadcom Symantec Messaging Gateway Security Vulnerabilities
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before
CVE-2024-23614
9.8 - Critical
- January 26, 2024
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root.
Classic Buffer Overflow
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before
CVE-2024-23615
9.8 - Critical
- January 26, 2024
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root.
Classic Buffer Overflow
A malicious authenticated SMG administrator user can obtain passwords for external LDAP/Active Directory servers
CVE-2021-30651
4.9 - Medium
- June 24, 2022
A malicious authenticated SMG administrator user can obtain passwords for external LDAP/Active Directory servers that they might not otherwise be authorized to access.
A privilege escalation flaw
CVE-2020-12594
7.2 - High
- December 10, 2020
A privilege escalation flaw allows a malicious, authenticated, privileged CLI user to escalate their privileges on the system and gain full control over the SMG appliance. This affects SMG prior to 10.7.4.
Improper Privilege Management
An information disclosure flaw allows a malicious, authenticated, privileged web UI user to obtain a password for a remote SCP backup server
CVE-2020-12595
4.9 - Medium
- December 10, 2020
An information disclosure flaw allows a malicious, authenticated, privileged web UI user to obtain a password for a remote SCP backup server that they might not otherwise be authorized to access. This affects SMG prior to 10.7.4.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Broadcom Symantec Messaging Gateway or by Broadcom? Click the Watch button to subscribe.