CVE-2020-12595: Medium severity symantec messaging gateway for service providers vulnerability
Published Dec 10, 2020
·Updated
An information disclosure flaw allows a malicious, authenticated, privileged web UI user to obtain a password for a remote SCP backup server that they might not otherwise be authorized to access. This affects SMG prior to 10.7.4.
Affected Software
1 affected component
Broadcom Symantec Messaging Gateway<10.7.4
Event History
Dec 10, 2020
CVE Published
via MITRE·05:21 AM
Data Sourced
via MITRE·05:21 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-12595?
CVE-2020-12595 has been evaluated as a medium severity vulnerability.
2
How do I fix CVE-2020-12595?
To mitigate CVE-2020-12595, upgrade your Symantec Messaging Gateway to version 10.7.4 or later.
3
What type of vulnerability is CVE-2020-12595?
CVE-2020-12595 is classified as an information disclosure vulnerability.
4
Who is affected by CVE-2020-12595?
CVE-2020-12595 affects users of Broadcom Symantec Messaging Gateway versions prior to 10.7.4.
5
What is the impact of CVE-2020-12595?
The impact of CVE-2020-12595 allows a malicious authenticated user to gain unauthorized access to a remote SCP backup server password.