First published: Thu Apr 09 2020(Updated: )
The ASG and ProxySG management consoles are susceptible to a session hijacking vulnerability. A remote attacker, with access to the appliance management interface, can hijack the session of a currently logged-in user and access the management console.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Symantec Advanced Secure Gateway | >=6.7.4<6.7.4.10 | |
Broadcom Symantec Advanced Secure Gateway | >=7.1<7.2.0.1 | |
Broadcom ProxySG | >=6.7.4<6.7.4.10 | |
Broadcom ProxySG | >=7.1<7.2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18375 is a session hijacking vulnerability in the ASG and ProxySG management consoles.
A remote attacker, with access to the appliance management interface, can hijack the session of a currently logged-in user and access the management console.
Broadcom Advanced Secure Gateway (ASG) versions 6.7.4 to 6.7.4.10, 7.1 to 7.2.0.1, and Broadcom Symantec ProxySG versions 6.7.4 to 6.7.4.10, 7.1 to 7.2.0.1 are affected.
CVE-2019-18375 has a severity score of 6.5, which is considered medium.
Users should upgrade to a fixed version of the affected software provided by Broadcom.