HTTP: Symantec Web Gateway OS Command Injection

A command injection vulnerability exists in Symantec Web Gateway. A remote authenticated attacker can leverage this vulnerability to inject and execute commands with root privileges.

Extended Description

Symantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users to execute arbitrary OS commands.

Affected Products

Symantec web_gateway

Short Name
HTTP:MISC:SYM-WEB-CMD-INJ
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2016-5313 Command Gateway Injection OS Symantec Web
Release Date
11/10/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Symantec

CVSS Score

9.0

Found a potential security threat?