CVE-2021-46825
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Symantec Advanced Secure Gateway (ASG) and ProxySG are susceptible to an HTTP desync vulnerability. When a remote unauthenticated attacker and other web clients communicate through the proxy with the same web server, the attacker can send crafted HTTP requests and cause the proxy to forward web server responses to unintended clients. Severity/CVSSv3: High / 8.1 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Symantec Advanced Secure Gateway (ASG) y ProxySG son susceptibles a una vulnerabilidad de desincronización HTTP. Cuando un atacante remoto no autenticado y otros clientes web se comunican a mediante el proxy con el mismo servidor web, el atacante puede enviar peticiones HTTP diseñadas y causar que el proxy reenvíe las respuestas del servidor web a clientes no deseados. Gravedad/CVSSv3: Alta / 8.1 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-06-29 CVE Reserved
- 2022-07-07 CVE Published
- 2024-08-04 CVE Updated
- 2024-09-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Broadcom Search vendor "Broadcom" | Advanced Secure Gateway Search vendor "Broadcom" for product "Advanced Secure Gateway" | 6.7 Search vendor "Broadcom" for product "Advanced Secure Gateway" and version "6.7" | - |
Affected
| ||||||
Broadcom Search vendor "Broadcom" | Advanced Secure Gateway Search vendor "Broadcom" for product "Advanced Secure Gateway" | 7.3 Search vendor "Broadcom" for product "Advanced Secure Gateway" and version "7.3" | - |
Affected
| ||||||
Broadcom Search vendor "Broadcom" | Proxysg Search vendor "Broadcom" for product "Proxysg" | 6.7 Search vendor "Broadcom" for product "Proxysg" and version "6.7" | - |
Affected
| ||||||
Broadcom Search vendor "Broadcom" | Proxysg Search vendor "Broadcom" for product "Proxysg" | 7.3 Search vendor "Broadcom" for product "Proxysg" and version "7.3" | - |
Affected
|