Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8586-qhh3-x99v

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator user into downloading and executing malicious code.

Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator user into downloading and executing malicious code.

EPSS

Процентиль: 93%
0.10463
Средний

6.8 Medium

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 6.8
nvd
почти 8 лет назад

Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator user into downloading and executing malicious code.

EPSS

Процентиль: 93%
0.10463
Средний

6.8 Medium

CVSS3

Дефекты

CWE-434