CVE-2016-2204: High severity symantec messaging gateway for service providers vulnerability
Published Apr 22, 2016
·Updated
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to obtain root-shell access via crafted terminal-window input.
Affected Software
7 affected components
Symantec Messaging Gateway<=10.6.0
Symantec Messaging Gateway=10.6.0-1
Symantec Messaging Gateway=10.6.0-2
Symantec Messaging Gateway=10.6.0-3
Symantec Messaging Gateway=10.6.0-4
Symantec Messaging Gateway=10.6.0-5
Symantec Messaging Gateway=10.6.0-6
Event History
Apr 22, 2016
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2204?
CVE-2016-2204 is classified as a high severity vulnerability due to its potential to allow local users to gain root-shell access.
2
How do I fix CVE-2016-2204?
To mitigate CVE-2016-2204, upgrade your Symantec Messaging Gateway to version 10.6.1 or later.
3
Who is affected by CVE-2016-2204?
CVE-2016-2204 affects users of Symantec Messaging Gateway devices running versions prior to 10.6.1.
4
What type of access does CVE-2016-2204 allow?
CVE-2016-2204 allows a local user to obtain root-shell access through crafted terminal-window input.
5
Is there a workaround for CVE-2016-2204?
There are no known workarounds for CVE-2016-2204; the only solution is to upgrade to an unaffected version.