Broadcom
Broadcom Symantec Messaging Gateway: vulnerabilidades y CVE
Broadcom Symantec Messaging Gateway tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses0
Críticas2
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2014-0160 | Alta (7.5) | 100% | ⚠ Explotación activa | 7 abr 2014 | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-23615 | Crítica (9.8) | 1.9% | — | 26 ene 2024 | A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root. |
| CVE-2024-23614 | Crítica (9.8) | 1.6% | — | 26 ene 2024 | A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root. |
| CVE-2021-30651 | Media (4.9) | 0.73% | — | 24 jun 2022 | A malicious authenticated SMG administrator user can obtain passwords for external LDAP/Active Directory servers that they might not otherwise be authorized to access. |
| CVE-2020-12595 | Media (4.9) | 0.87% | — | 10 dic 2020 | An information disclosure flaw allows a malicious, authenticated, privileged web UI user to obtain a password for a remote SCP backup server that they might not otherwise be authorized to access. This affects SMG prior… |
| CVE-2020-12594 | Alta (7.2) | 1.5% | — | 10 dic 2020 | A privilege escalation flaw allows a malicious, authenticated, privileged CLI user to escalate their privileges on the system and gain full control over the SMG appliance. This affects SMG prior to 10.7.4. |
| CVE-2014-0160 | Alta (7.5) | 100% | ⚠ Explotación activa | 7 abr 2014 | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Broadcom
Fabric Operating System · 95Brocade Sannav · 54Tcpreplay · 52Brightstor Arcserve Backup · 41Brocade Fabric Operating System Firmware · 26Rabbitmq Server · 25Raid Controller WEB Interface · 22Sannav · 20Brightstor Enterprise Backup · 19Advanced Secure Gateway · 16Business Protection Suite · 16Etrust Antivirus · 16