A malicious authenticated SMG administrator user can obtain passwords for external LDAP/Active Directory servers that they might not otherwise be authorized to access.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NBroadcom Symantec Messaging Gateway
APPBroadcom10.7 – 10.7.5 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2024-23614CRITICAL10.0PL ✓same product
Buffer overflow w Broadcom Symantec Messaging Gateway umożliwiający RCE jako root
CVE-2024-23615CRITICAL10.0PL ✓same product
Buffer overflow w Broadcom Symantec Messaging Gateway umożliwiający RCE jako root
CVE-2014-0160HIGH7.5⚠ KEVsame product
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Exten...
CVE-2020-12594HIGH7.2same product
A privilege escalation flaw allows a malicious, authenticated, privileged CLI user to escalate their privilege...
CVE-2020-12595MEDIUM4.9same product
An information disclosure flaw allows a malicious, authenticated, privileged web UI user to obtain a password ...