First published: Thu Jun 01 2023(Updated: )
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability.
Credit: secure@symantec.com secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
broadcom advanced secure gateway | <7.3.13.1 | |
broadcom Content Analysis | <3.1.6.0 | |
Broadcom Symantec Advanced Secure Gateway | <7.3.13.1 | |
Broadcom Content Analysis | <3.1.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23952 is a Command Injection vulnerability found in Advanced Secure Gateway and Content Analysis prior to 7.3.13.1 / 3.1.6.0.
CVE-2023-23952 has a severity score of 9.8 (critical).
Advanced Secure Gateway versions prior to 7.3.13.1 and Content Analysis versions prior to 3.1.6.0 are affected by CVE-2023-23952.
The CWE ID for CVE-2023-23952 is CWE-77 (Improper Neutralization of Special Elements used in a Command ('Command Injection')).
To fix CVE-2023-23952, it is recommended to update Advanced Secure Gateway to version 7.3.13.1 or later, and Content Analysis to version 3.1.6.0 or later.