CVE-2016-10258: Malicious File Upload
Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator user into downloading and executing malicious code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10258?
The severity of CVE-2016-10258 is medium.
Which software versions are affected by CVE-2016-10258?
CVE-2016-10258 affects Broadcom Advanced Secure Gateway versions 6.6 to 6.6.5.14, Broadcom Advanced Secure Gateway versions 6.7 to 6.7.3.1, Broadcom Symantec Proxysg versions 6.5 to 6.5.10.8, and Broadcom Symantec Proxysg versions 6.6 to 6.6.5.14.
What is the vulnerability in CVE-2016-10258?
CVE-2016-10258 is an unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles.
How can an attacker exploit CVE-2016-10258?
An attacker can exploit CVE-2016-10258 by uploading arbitrary malicious files to the management console and tricking another administrator user into downloading and executing the malicious code.
Are there any references for CVE-2016-10258?
Yes, you can find references for CVE-2016-10258 at the following URLs: [1](http://www.securityfocus.com/bid/103685), [2](http://www.securitytracker.com/id/1040757), [3](https://www.symantec.com/security-center/network-protection-security-advisories/SA162).