First published: Thu Aug 01 2013(Updated: )
The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote attackers to execute arbitrary commands by injecting a command into an application script.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Web Gateway | <=5.1 | |
Symantec Web Gateway | =5.0 | |
Symantec Web Gateway | =5.0.1 | |
Symantec Web Gateway | =5.0.2 | |
Symantec Web Gateway | =5.0.3 | |
Symantec Web Gateway | =5.0.3.18 | |
Symantec Web Gateway Appliance 8450 | ||
Symantec Web Gateway Appliance 8490 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1616 is considered to be a critical vulnerability due to its potential for remote command execution.
To remediate CVE-2013-1616, update the Symantec Web Gateway appliance to version 5.1.1 or later.
CVE-2013-1616 impacts various versions of Symantec Web Gateway, particularly those prior to 5.1.1.
Yes, CVE-2013-1616 allows remote attackers to execute arbitrary commands, leading to potential unauthorized access.
If you cannot update, consider implementing network segmentation and strict access controls to mitigate the risks associated with CVE-2013-1616.