HTTP: Symantec Messaging Gateway Cross Site Request Forgery

This signature detects attempts to exploit a known vulnerability against Symantec Messaging Gateway. A successful attack can result in a cross site request forgery.

Extended Description

The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbreviated as CSRF or XSRF), which is a type of malicious exploit of a website where unauthorized commands are transmitted from a user that the web application trusts. A CSRF attack attempts to exploit the trust that a specific website has in a user's browser.

Affected Products

Symantec message_gateway

References

BugTraq: 100136

CVE: CVE-2017-6328

Short Name
HTTP:CTS:SYMANTEC-MSG-GW-CSRF
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2017-6328 Cross Forgery Gateway Messaging Request Site Symantec bid:100136
Release Date
06/16/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3415
False Positive
Unknown
Vendors

Symantec

CVSS Score

6.8

Found a potential security threat?