« Volver al listado

CVE-2017-13678

Estado: ModificadaMedia (4.8)—

Stored XSS vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can inject arbitrary JavaScript code in the management console web client application.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-13678",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 4.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 1.7
      }
    ]
  },
  "affected": [
    {
      "source": "secure@symantec.com",
      "affectedData": [
        {
          "vendor": "Symantec Corporation",
          "product": "Advanced Secure Gateway (ASG)",
          "versions": [
            {
              "status": "affected",
              "version": "6.6 prior to 6.6.5.14"
            },
            {
              "status": "affected",
              "version": "6.7 prior to 6.7.4.107"
            }
          ]
        },
        {
          "vendor": "Symantec Corporation",
          "product": "ProxySG",
          "versions": [
            {
              "status": "affected",
              "version": "6.5 prior to 6.5.10.8"
            },
            {
              "status": "affected",
              "version": "6.6 prior to 6.6.5.14"
            },
            {
              "status": "affected",
              "version": "6.7 prior to 6.7.4.107"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-04-11T14:29:00.377",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/103685",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "secure@symantec.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1040757",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "secure@symantec.com"
    },
    {
      "url": "https://www.symantec.com/security-center/network-protection-security-advisories/SA162",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@symantec.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/103685",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1040757",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.symantec.com/security-center/network-protection-security-advisories/SA162",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Stored XSS vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can inject arbitrary JavaScript code in the management console web client application."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de Cross-Site Scripting (XSS) persistente en las consolas de gestión Symantec Advanced Secure Gateway (ASG) y ProxySG. Un administrador de aparatos malicioso puede inyectar código JavaScript arbitrario en la aplicación cliente de la consola de gestión web."
    }
  ],
  "lastModified": "2026-06-17T01:04:58.223",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:broadcom:advanced_secure_gateway:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EF86C5BD-ABB2-4B5D-901D-42153FB2ED15",
              "versionEndExcluding": "6.6.5.14",
              "versionStartIncluding": "6.6"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:advanced_secure_gateway:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D365F8C-3F0E-4596-9AE0-840E966E7E2C",
              "versionEndExcluding": "6.7.3.7",
              "versionStartIncluding": "6.7.3"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:advanced_secure_gateway:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FCD17841-CC52-427D-9B77-B3787276D1FE",
              "versionEndExcluding": "6.7.4.107",
              "versionStartIncluding": "6.7.4"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:broadcom:symantec_proxysg:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71233B55-5E11-42A3-AE39-EAD381E32607",
              "versionEndExcluding": "6.5.10.8",
              "versionStartIncluding": "6.5"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:symantec_proxysg:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2D262D81-F928-4847-87C8-D20849ABA94F",
              "versionEndExcluding": "6.6.5.14",
              "versionStartIncluding": "6.6"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:symantec_proxysg:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A161CEF7-078D-400B-82FF-F4CCD5561F09",
              "versionEndExcluding": "6.7.3.7",
              "versionStartIncluding": "6.7.3"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:symantec_proxysg:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F473B1BD-A298-4809-AAB1-E7B520AA5222",
              "versionEndExcluding": "6.7.4.107",
              "versionStartIncluding": "6.7.4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@symantec.com"
}