CVE-2019-18375: Medium severity broadcom symantec advanced secure gateway vulnerability
The ASG and ProxySG management consoles are susceptible to a session hijacking vulnerability. A remote attacker, with access to the appliance management interface, can hijack the session of a currently logged-in user and access the management console.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-18375?
CVE-2019-18375 is a session hijacking vulnerability in the ASG and ProxySG management consoles.
How does CVE-2019-18375 work?
A remote attacker, with access to the appliance management interface, can hijack the session of a currently logged-in user and access the management console.
Which software is affected by CVE-2019-18375?
Broadcom Advanced Secure Gateway (ASG) versions 6.7.4 to 6.7.4.10, 7.1 to 7.2.0.1, and Broadcom Symantec ProxySG versions 6.7.4 to 6.7.4.10, 7.1 to 7.2.0.1 are affected.
What is the severity of CVE-2019-18375?
CVE-2019-18375 has a severity score of 6.5, which is considered medium.
How can I fix CVE-2019-18375?
Users should upgrade to a fixed version of the affected software provided by Broadcom.