CVE-2021-46825: Critical severity broadcom symantec advanced secure gateway vulnerability
Symantec Advanced Secure Gateway (ASG) and ProxySG are susceptible to an HTTP desync vulnerability. When a remote unauthenticated attacker and other web clients communicate through the proxy with the same web server, the attacker can send crafted HTTP requests and cause the proxy to forward web server responses to unintended clients. Severity/CVSSv3: High / 8.1 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-46825?
CVE-2021-46825 is an HTTP desync vulnerability in Symantec Advanced Secure Gateway (ASG) and ProxySG.
What is the severity of CVE-2021-46825?
The severity of CVE-2021-46825 is critical, with a severity score of 9.1.
Which software versions are affected by CVE-2021-46825?
CVE-2021-46825 affects Broadcom Advanced Secure Gateway versions 6.7 and 7.3, as well as Broadcom Proxysg versions 6.7 and 7.3.
How does CVE-2021-46825 work?
CVE-2021-46825 allows a remote unauthenticated attacker to send crafted HTTP requests through the proxy, causing it to forward web server responses or cache them incorrectly.
How can I fix CVE-2021-46825?
To fix CVE-2021-46825, it is recommended to apply the patches or updates provided by Broadcom and follow any mitigation steps provided in the security advisory.