CVE-2016-9097: High severity broadcom symantec advanced secure gateway vulnerability
The Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.8, ProxySG 6.5 prior 6.5.10.6, ProxySG 6.6 prior to 6.6.5.8, and ProxySG 6.7 prior to 6.7.1.2 management consoles do not, under certain circumstances, correctly authorize administrator users. A malicious administrator with read-only access can exploit this vulnerability to access management console functionality that requires read-write access privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9097?
CVE-2016-9097 is classified as a high-severity vulnerability due to improper authorization of administrator users.
How do I fix CVE-2016-9097?
To fix CVE-2016-9097, upgrade to Symantec Advanced Secure Gateway version 6.6.5.8 or higher, or ProxySG version 6.5.10.6 or higher.
Which versions are affected by CVE-2016-9097?
CVE-2016-9097 affects Symantec Advanced Secure Gateway versions prior to 6.6.5.8 and ProxySG versions prior to 6.5.10.6.
What systems are vulnerable to CVE-2016-9097?
The vulnerable systems include Symantec Advanced Secure Gateway and ProxySG management consoles prior to their respective patched versions.
Can CVE-2016-9097 be exploited remotely?
Yes, CVE-2016-9097 can be exploited by a malicious administrator with read-only access to gain unauthorized control.