ZeroHour

CVE-2016-10258

CVSS 3.0
6.8 medium
EPSS
5%p92
Published
()
Modified
Description

Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator user into downloading and executing malicious code.

Vendors
broadcom
Products
advanced secure gateway, symantec proxysg
Weakness
CWE-434
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.