CVE-2012-2977: Medium severity Symantec Web Gateway vulnerability
Published Jul 23, 2012
·Updated
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwords via crafted input to an application script.
Affected Software
4 affected components
Symantec Web Gateway=5.0
Symantec Web Gateway=5.0.1
Symantec Web Gateway=5.0.2
Symantec Web Gateway=5.0.3
Event History
Jul 23, 2012
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2977?
CVE-2012-2977 has a medium severity rating due to the potential for unauthorized password changes.
2
How do I fix CVE-2012-2977?
To fix CVE-2012-2977, upgrade Symantec Web Gateway to version 5.0.3.18 or later.
3
What versions of Symantec Web Gateway are affected by CVE-2012-2977?
Versions 5.0, 5.0.1, 5.0.2, and 5.0.3 of Symantec Web Gateway are affected by CVE-2012-2977.
4
Can CVE-2012-2977 be exploited remotely?
Yes, CVE-2012-2977 can be exploited remotely by sending crafted input to the management console.
5
Is there a patch available for CVE-2012-2977?
Yes, a patch is included in Symantec Web Gateway version 5.0.3.18 and later to address CVE-2012-2977.