« Volver al listado

CVE-2016-6594

Estado: ModificadaAlta (7.5)—

Blue Coat Advanced Secure Gateway 6.6, CacheFlow 3.4, ProxySG 6.5 and 6.6 allows remote attackers to bypass blocked requests, user authentication, and payload scanning.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-6594",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "secure@symantec.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-06-08T20:29:00.280",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/91404",
      "source": "secure@symantec.com"
    },
    {
      "url": "https://bto.bluecoat.com/security-advisory/sa130",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "secure@symantec.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/91404",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bto.bluecoat.com/security-advisory/sa130",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-254"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Blue Coat Advanced Secure Gateway 6.6, CacheFlow 3.4, ProxySG 6.5 and 6.6 allows remote attackers to bypass blocked requests, user authentication, and payload scanning."
    },
    {
      "lang": "es",
      "value": "Blue Coat Advanced Secure Gateway 6.6, CacheFlow 3.4, ProxySG versiones 6.5 y 6.6 permite a los atacantes remotos evitar las solicitudes bloqueadas, la autenticación del usuario y el escaneo de la carga útil."
    }
  ],
  "lastModified": "2026-06-17T00:51:25.410",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:bluecoat:advanced_secure_gateway:6.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C5CF6DF9-AF0F-455D-8268-F6A6D6241D03"
            },
            {
              "criteria": "cpe:2.3:a:bluecoat:cacheflow:3.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "394EE24C-FD34-4346-862F-90306C352185"
            },
            {
              "criteria": "cpe:2.3:a:bluecoat:proxysg:6.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2C7C7AB7-603E-4499-8C9B-C280C354C7BD"
            },
            {
              "criteria": "cpe:2.3:a:bluecoat:proxysg:6.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6675B614-BFD6-4B5E-85AA-95D402E8B3E2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@symantec.com"
}