First published: Fri Jun 24 2022(Updated: )
A malicious authenticated SMG administrator user can obtain passwords for external LDAP/Active Directory servers that they might not otherwise be authorized to access.
Credit: secure@symantec.com secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Symantec Messaging Gateway | >=10.7<10.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-30651 is rated as a high severity vulnerability due to the potential unauthorized access to sensitive credentials.
To mitigate CVE-2021-30651, upgrade to Broadcom Symantec Messaging Gateway version 10.7.5 or later.
CVE-2021-30651 affects systems running Broadcom Symantec Messaging Gateway versions before 10.7.5.
No, CVE-2021-30651 requires the attacker to be an authenticated SMG administrator user.
If affected by CVE-2021-30651, immediately upgrade your Symantec Messaging Gateway and review access logs for unauthorized activities.