CVE-2016-9099
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 prior to 6.7.2.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6, and ProxySG 6.7 prior to 6.7.2.1 are susceptible to an open redirection vulnerability. A remote attacker can use a crafted management console URL in a phishing attack to redirect the target user to a malicious web site.
Advanced Secure Gateway (ASG) versión 6.6, ASG versiones 6.7 anteriores a 6.7.2.1, ProxySG versiones 6.5 anteriores a 6.5.10.6, ProxySG versión 6.6 y ProxySG versiones 6.7 anteriores a 6.7.2.1 de Symantec, son susceptibles a una vulnerabilidad de redireccionamiento abierto. Un atacante remoto puede usar una URL diseñada de la consola de administración en un ataque de phishing para redireccionar al usuario destino hacia un sitio web malicioso.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-10-28 CVE Reserved
- 2017-05-11 CVE Published
- 2023-03-07 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/102455 | Third Party Advisory | |
http://www.securitytracker.com/id/1040138 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.symantec.com/security-center/network-protection-security-advisories/SA155 | 2021-07-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Broadcom Search vendor "Broadcom" | Advanced Secure Gateway Search vendor "Broadcom" for product "Advanced Secure Gateway" | >= 6.7 < 6.7.2.1 Search vendor "Broadcom" for product "Advanced Secure Gateway" and version " >= 6.7 < 6.7.2.1" | - |
Affected
| ||||||
Broadcom Search vendor "Broadcom" | Symantec Proxysg Search vendor "Broadcom" for product "Symantec Proxysg" | >= 6.5 < 6.5.10.6 Search vendor "Broadcom" for product "Symantec Proxysg" and version " >= 6.5 < 6.5.10.6" | - |
Affected
| ||||||
Broadcom Search vendor "Broadcom" | Advanced Secure Gateway Search vendor "Broadcom" for product "Advanced Secure Gateway" | 6.6 Search vendor "Broadcom" for product "Advanced Secure Gateway" and version "6.6" | - |
Affected
| ||||||
Broadcom Search vendor "Broadcom" | Symantec Proxysg Search vendor "Broadcom" for product "Symantec Proxysg" | 6.6 Search vendor "Broadcom" for product "Symantec Proxysg" and version "6.6" | - |
Affected
| ||||||
Broadcom Search vendor "Broadcom" | Symantec Proxysg Search vendor "Broadcom" for product "Symantec Proxysg" | >= 6.7 < 6.7.2.1 Search vendor "Broadcom" for product "Symantec Proxysg" and version " >= 6.7 < 6.7.2.1" | - |
Affected
|