CVE-2015-5690
UnknownEPSS 3.50%
Last modified
CVE-2015-5690 is a vulnerability of currently unknown severity. The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging a "redirect.". EPSS estimates a 3.50% chance of exploitation in the next 30 days.
Description
The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging a "redirect."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Symantec | Web Gateway | <= 5.2.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-5690?
The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging a "redirect."
How severe is CVE-2015-5690?
Severity scoring for CVE-2015-5690 is pending analysis. The EPSS model estimates a 3.50% probability of exploitation in the next 30 days.
How do I fix CVE-2015-5690?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-5684MITRE is populating this ID because it was assigned prior to…9.8
- CVE-2015-5685The lazy_bdecode function in BitTorrent DHT bootstrap server…
- CVE-2015-5686Parts of the Puppet Enterprise Console 3.x were found to be …8.8
- CVE-2015-5687system/session/drivers/cookie.php in Anchor CMS 0.9.x allows…
- CVE-2015-5688Directory traversal vulnerability in lib/app/index.js in Ged…
- CVE-2015-5689ghostexp.exe in Ghost Explorer Utility in Symantec Ghost Sol…
- CVE-2015-5691Multiple cross-site scripting (XSS) vulnerabilities in PHP s…
- CVE-2015-5692admin_messages.php in the management console on Symantec Web…
- CVE-2015-5693The management console on Symantec Web Gateway (SWG) applian…
- CVE-2015-5694Designate does not enforce the DNS protocol limit concerning…6.5
- CVE-2015-5695Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStac…
- CVE-2015-5696Dell Netvault Backup before 10.0.5 allows remote attackers t…
Are you affected by CVE-2015-5690?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
