Vulnerability Name: | CVE-2014-7285 (CCN-99608) | ||||||||
Assigned: | 2014-12-16 | ||||||||
Published: | 2014-12-16 | ||||||||
Updated: | 2017-01-03 | ||||||||
Summary: | The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts. | ||||||||
CVSS v3 Severity: | 7.6 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P) 5.4 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:F/RL:OF/RC:C)
5.4 Medium (CCN Temporal CVSS v2 Vector: AV:A/AC:H/Au:S/C:C/I:C/A:C/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-77 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-7285 Source: MISC Type: UNKNOWN http://karmainsecurity.com/KIS-2014-19 Source: OSVDB Type: UNKNOWN 116009 Source: MISC Type: UNKNOWN http://packetstormsecurity.com/files/130612/Symantec-Web-Gateway-5-restore.php-Command-Injection.html Source: EXPLOIT-DB Type: UNKNOWN 36263 Source: BID Type: UNKNOWN 71620 Source: CCN Type: BID-71620 Symantec Web Gateway CVE-2014-7285 Command Injection Vulnerability Source: SECTRACK Type: UNKNOWN 1031386 Source: CCN Type: Symantec Security Advisory SYM14-016 Symantec Web Gateway OS Authenticated Command Injection Source: CONFIRM Type: Vendor Advisory http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20141216_00 Source: XF Type: UNKNOWN symantec-gateway-cve20147285-command-exec(99608) Source: CCN Type: Packet Storm Security [12-31-2014] Symantec Web Gateway 5.2.1 OS Command Injection Source: CCN Type: Packet Storm Security [03-03-2015] Symantec Web Gateway 5 restore.php Command Injection Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [03-04-2015] | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |