First published: Wed Jul 31 2013(Updated: )
The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 has an incorrect sudoers file, which allows local users to bypass intended access restrictions via a command.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Web Gateway | <=5.1 | |
Symantec Web Gateway | =5.0 | |
Symantec Web Gateway | =5.0.1 | |
Symantec Web Gateway | =5.0.2 | |
Symantec Web Gateway | =5.0.3 | |
Symantec Web Gateway | =5.0.3.18 | |
Symantec Web Gateway Appliance 8450 | ||
Symantec Web Gateway Appliance 8490 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4672 is classified as a moderate severity vulnerability due to the potential for local users to gain unauthorized access.
To fix CVE-2013-4672, update the Symantec Web Gateway to version 5.1.1 or later.
CVE-2013-4672 affects Symantec Web Gateway versions prior to 5.1.1, including 5.0 and its subversions.
Yes, CVE-2013-4672 could potentially lead to data breaches by allowing local users to bypass access restrictions.
Organizations using affected versions of Symantec Web Gateway are at risk due to the vulnerability in the management console.