Vulnerabilities (CVE)

Filtered by vendor Broadcom Subscribe
Filtered by product Symantec Messaging Gateway
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-23615 1 Broadcom 1 Symantec Messaging Gateway 2024-01-31 10.0 HIGH 9.8 CRITICAL
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root.
CVE-2024-23614 1 Broadcom 1 Symantec Messaging Gateway 2024-01-31 9.4 HIGH 9.8 CRITICAL
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root.
CVE-2021-30651 1 Broadcom 1 Symantec Messaging Gateway 2023-12-10 4.0 MEDIUM 4.9 MEDIUM
A malicious authenticated SMG administrator user can obtain passwords for external LDAP/Active Directory servers that they might not otherwise be authorized to access.
CVE-2020-12594 1 Broadcom 1 Symantec Messaging Gateway 2023-12-10 9.0 HIGH 7.2 HIGH
A privilege escalation flaw allows a malicious, authenticated, privileged CLI user to escalate their privileges on the system and gain full control over the SMG appliance. This affects SMG prior to 10.7.4.
CVE-2020-12595 1 Broadcom 1 Symantec Messaging Gateway 2023-12-10 4.0 MEDIUM 4.9 MEDIUM
An information disclosure flaw allows a malicious, authenticated, privileged web UI user to obtain a password for a remote SCP backup server that they might not otherwise be authorized to access. This affects SMG prior to 10.7.4.