First published: Wed Jul 31 2013(Updated: )
Cross-site request forgery (CSRF) vulnerability in the management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Web Gateway | <=5.1 | |
Symantec Web Gateway | =5.0 | |
Symantec Web Gateway | =5.0.1 | |
Symantec Web Gateway | =5.0.2 | |
Symantec Web Gateway | =5.0.3 | |
Symantec Web Gateway | =5.0.3.18 | |
Symantec Web Gateway Appliance 8450 | ||
Symantec Web Gateway Appliance 8490 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4671 is classified as a moderate severity vulnerability due to its cross-site request forgery nature.
To fix CVE-2013-4671, update your Symantec Web Gateway appliance to version 5.1.1 or later.
CVE-2013-4671 affects users of Symantec Web Gateway appliances prior to version 5.1.1.
CVE-2013-4671 is a cross-site request forgery (CSRF) vulnerability.
Yes, CVE-2013-4671 can be exploited by remote authenticated users.