CVE-2017-6327
KEVlargeInput Validation RCE in Symantec Messaging Gateway
CISA: Symantec Messaging Gateway Remote Code Execution Vulnerability
CVE-2017-6327 is an input-validation flaw (CWE-20) in Symantec Messaging Gateway that allows remote code execution; the exact vulnerable code path is not described in the available data. Because the flaw is remotely triggerable, an attacker who can reach the vulnerable component can execute code on the appliance and may then pursue privilege escalation to gain higher-level access on the host. Affected organizations are those running Symantec Messaging Gateway, with risk concentrated where the appliance or its administrative interface is reachable from untrusted networks. The vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 with a required action to apply updates per vendor instructions, and EPSS assigns a high 35.3% probability of exploitation within 30 days (98th percentile); no public proof-of-concept is known and any ransomware association is unconfirmed.
What to do: Apply updates per vendor instructions as soon as possible, since CISA's KEV listing requires federal agencies to patch and the flaw is known exploited. In the interim, verify whether the Symantec Messaging Gateway management/administrative interface is exposed to the internet and restrict access to trusted management networks, and review appliance logs for signs of unauthorized access or code execution. Because a fixed version is not specified in the available data, confirm the current patched release with the vendor's (Symantec/Broadcom) security advisory before remediating.
| Symantec Messaging Gateway | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. In this type of occurrence, after gaining access to the system, the attacker may attempt to elevate their privileges.
- Affected
- Symantec Symantec Messaging Gateway
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- symantec
- Products
- message gateway
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H