vendor:
Symantec Messaging Gateway
by:
Anonymous
8,8
CVSS
HIGH
Unauthenticated Remote Code Execution
287
CWE
Product Name: Symantec Messaging Gateway
Affected Version From: 10.6.3-2
Affected Version To: 10.6.3-2
Patch Exists: YES
Related CWE: CVE-2017-6327
CPE: a:symantec:symantec_messaging_gateway
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2017
CVE-2017-6327
Symantec Messaging Gateway prior to and including version 10.6.3-2 contains an unauthenticated remote code execution vulnerability in the web interface. An attacker can construct a GET request to '/brightmail/action1.do?method=notificationLogin' with an encrypted version of the username they want to log in as, and set the JSESSIONID cookie to the current session. This will log the attacker in as the specified user.
Mitigation:
Symantec released a patch and notice for this vulnerability on 2017-08-10.