CVE-2012-0299: Critical severity symantec web gateway appliance vulnerability
Published May 21, 2012
·Updated
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code to a designated pathname, and possibly execute this code, via unspecified vectors.
Affected Software
3 affected components
Symantec Web Gateway=5.0
Symantec Web Gateway=5.0.1
Symantec Web Gateway=5.0.2
Event History
May 21, 2012
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0299?
CVE-2012-0299 is classified as a critical vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2012-0299?
To fix CVE-2012-0299, upgrade to Symantec Web Gateway version 5.0.3 or later.
3
What systems are affected by CVE-2012-0299?
CVE-2012-0299 affects Symantec Web Gateway versions 5.0, 5.0.1, and 5.0.2.
4
What type of attack does CVE-2012-0299 facilitate?
CVE-2012-0299 facilitates remote code execution by allowing attackers to upload arbitrary files.
5
When was CVE-2012-0299 discovered?
CVE-2012-0299 was disclosed and documented in May 2012.