CVE-2021-30648: Critical severity broadcom proxysg vulnerability
The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthenticated attacker can execute arbitrary CLI commands, view/modify the appliance configuration and policy, and shutdown/restart the appliance.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-30648?
CVE-2021-30648 refers to an authentication bypass vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles.
Who is affected by CVE-2021-30648?
Users of Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are affected by CVE-2021-30648.
What is the severity of CVE-2021-30648?
CVE-2021-30648 has a severity rating of 9.8, which is considered critical.
How can an attacker exploit CVE-2021-30648?
An unauthenticated attacker can exploit CVE-2021-30648 by executing arbitrary CLI commands, modifying the appliance configuration and policy, and shutting down/restarting the appliance.
Is there a fix for CVE-2021-30648?
Yes, it is recommended to update the affected software to versions that are not vulnerable. Refer to the vendor's security advisory for specific details and patches.