symantec advanced-secure-gateway CVE-2016-9097 in Symantec and Broadcom Products
Published on May 11, 2017

product logo product logo
The Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.8, ProxySG 6.5 prior 6.5.10.6, ProxySG 6.6 prior to 6.6.5.8, and ProxySG 6.7 prior to 6.7.1.2 management consoles do not, under certain circumstances, correctly authorize administrator users. A malicious administrator with read-only access can exploit this vulnerability to access management console functionality that requires read-write access privileges.

NVD


Products Associated with CVE-2016-9097

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2016-9097 are published in these products:

 
 
 

Affected Versions

Symantec Corporation Symantec Advanced Secure Gateway (ASG) and ProxySG Version ASG 6.6 prior to 6.6.5.8, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6 prior to 6.6.5.8, ProxySG 6.7 prior to 6.7.1.2 is affected by CVE-2016-9097

Exploit Probability

EPSS
1.22%
Percentile
78.85%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.