First published: Wed Apr 11 2018(Updated: )
Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator user into downloading and executing malicious code.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Symantec Advanced Secure Gateway | >=6.6<6.6.5.14 | |
Broadcom Symantec Advanced Secure Gateway | >=6.7<6.7.3.1 | |
Broadcom ProxySG | >=6.5<6.5.10.8 | |
Broadcom ProxySG | >=6.6<6.6.5.14 | |
Broadcom ProxySG | >=6.7<6.7.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-10258 is medium.
CVE-2016-10258 affects Broadcom Advanced Secure Gateway versions 6.6 to 6.6.5.14, Broadcom Advanced Secure Gateway versions 6.7 to 6.7.3.1, Broadcom Symantec Proxysg versions 6.5 to 6.5.10.8, and Broadcom Symantec Proxysg versions 6.6 to 6.6.5.14.
CVE-2016-10258 is an unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles.
An attacker can exploit CVE-2016-10258 by uploading arbitrary malicious files to the management console and tricking another administrator user into downloading and executing the malicious code.
Yes, you can find references for CVE-2016-10258 at the following URLs: [1](http://www.securityfocus.com/bid/103685), [2](http://www.securitytracker.com/id/1040757), [3](https://www.symantec.com/security-center/network-protection-security-advisories/SA162).