CVE-2012-0308: CSRF
Published Aug 29, 2012
·Updated
Cross-site request forgery (CSRF) vulnerability in Symantec Messaging Gateway (SMG) before 10.0 allows remote attackers to hijack the authentication of administrators.
Affected Software
6 affected components
Symantec Messaging Gateway<=9.5.4
Symantec Messaging Gateway=9.5
Symantec Messaging Gateway=9.5.1
Symantec Messaging Gateway=9.5.2
Symantec Messaging Gateway=9.5.3
Symantec Messaging Gateway=10.0
Event History
Aug 29, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0308?
CVE-2012-0308 is classified as a medium severity vulnerability due to its potential to allow unauthorized access to administrative functions.
2
How do I fix CVE-2012-0308?
To fix CVE-2012-0308, upgrade Symantec Messaging Gateway to version 10.0 or later.
3
What type of vulnerability is CVE-2012-0308?
CVE-2012-0308 is a cross-site request forgery (CSRF) vulnerability.
4
Who is affected by CVE-2012-0308?
Administrators using versions of Symantec Messaging Gateway prior to 10.0 are affected by CVE-2012-0308.
5
What can attackers do with CVE-2012-0308?
Attackers exploiting CVE-2012-0308 can hijack the authentication of administrators, potentially leading to unauthorized access.