CVE-2021-30651: Medium severity symantec messaging gateway for service providers vulnerability
Published Jun 24, 2022
·Updated
A malicious authenticated SMG administrator user can obtain passwords for external LDAP/Active Directory servers that they might not otherwise be authorized to access.
Affected Software
1 affected component
Broadcom Symantec Messaging Gateway>=10.7<10.7.5
Event History
Jun 24, 2022
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-30651?
CVE-2021-30651 is rated as a high severity vulnerability due to the potential unauthorized access to sensitive credentials.
2
How do I fix CVE-2021-30651?
To mitigate CVE-2021-30651, upgrade to Broadcom Symantec Messaging Gateway version 10.7.5 or later.
3
Who is affected by CVE-2021-30651?
CVE-2021-30651 affects systems running Broadcom Symantec Messaging Gateway versions before 10.7.5.
4
Can an unauthenticated user exploit CVE-2021-30651?
No, CVE-2021-30651 requires the attacker to be an authenticated SMG administrator user.
5
What should I do if I believe I have been affected by CVE-2021-30651?
If affected by CVE-2021-30651, immediately upgrade your Symantec Messaging Gateway and review access logs for unauthorized activities.