First published: Fri Apr 22 2016(Updated: )
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discover an encrypted AD password by leveraging certain read privileges.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Symantec Messaging Gateway | =10.6.0-patch3 | |
Broadcom Symantec Messaging Gateway | =10.6.0-patch5 | |
Broadcom Symantec Messaging Gateway | =10.6.0-patch7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2203 has a moderate severity level as it allows local users to discover sensitive information.
To fix CVE-2016-2203, upgrade to Symantec Messaging Gateway version 10.6.1 or later.
CVE-2016-2203 might allow local users to potentially retrieve encrypted Active Directory passwords.
CVE-2016-2203 affects Symantec Messaging Gateway versions 10.6.0 patched up to patch 7.
No, CVE-2016-2203 requires local access to the system to be exploited.