broadcom advanced-secure-gateway CVE-2021-46825 vulnerability in Broadcom Products
Published on July 7, 2022

Symantec Advanced Secure Gateway (ASG) and ProxySG are susceptible to an HTTP desync vulnerability. When a remote unauthenticated attacker and other web clients communicate through the proxy with the same web server, the attacker can send crafted HTTP requests and cause the proxy to forward web server responses to unintended clients. Severity/CVSSv3: High / 8.1 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

NVD


Products Associated with CVE-2021-46825

stack.watch emails you whenever new vulnerabilities are published in Broadcom Advanced Secure Gateway or Broadcom Proxysg. Just hit a watch button to start following.

 
 

Exploit Probability

EPSS
0.40%
Percentile
60.38%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.