CVE-2016-10257
Last modified
CVE-2016-10257 is a vulnerability of currently unknown severity. The Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 (prior to 6.7.2.1), ProxySG 6.5 (prior to 6.5.10.6), ProxySG 6.6, and ProxySG 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A remote attacker can use a crafted management console URL in a phishing attack to inject arbitrary JavaScript code into the management console web client application. EPSS estimates a 1.47% chance of exploitation in the next 30 days.
Description
The Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 (prior to 6.7.2.1), ProxySG 6.5 (prior to 6.5.10.6), ProxySG 6.6, and ProxySG 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A remote attacker can use a crafted management console URL in a phishing attack to inject arbitrary JavaScript code into the management console web client application. This is a separate vulnerability from CVE-2016-10256.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Advanced Secure Gateway | >= 6.7, < 6.7.2.1 |
| Broadcom | Advanced Secure Gateway | 6.6 |
| Broadcom | Symantec Proxysg | >= 6.5, < 6.5.10.6 |
| Broadcom | Symantec Proxysg | >= 6.7, < 6.7.2.1 |
| Broadcom | Symantec Proxysg | 6.6 |
References
- http://www.securityfocus.com/bid/102447Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040138Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/102447Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040138Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-10257?
How severe is CVE-2016-10257?
How do I fix CVE-2016-10257?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-10251Integer overflow in the jpc_pi_nextcprl function in jpc_t2co…
- CVE-2016-10252Memory leak in the IsOptionMember function in MagickCore/opt…
- CVE-2016-10253An issue was discovered in Erlang/OTP 18.x. Erlang's generat…
- CVE-2016-10254The allocate_elf function in common.h in elfutils before 0.1…
- CVE-2016-10255The __libelf_set_rawdata_wrlock function in elf_getdata.c in…
- CVE-2016-10256The Symantec ProxySG 6.5 (prior to 6.5.10.6), 6.6, and 6.7 (…
- CVE-2016-10258Unrestricted file upload vulnerability in the Symantec Advan…
- CVE-2016-10259Symantec SSL Visibility (SSLV) 3.8.4FC, 3.9, 3.10 before 3.1…
- CVE-2016-1026Adobe Flash Player before 18.0.0.343 and 19.x through 21.x b…8.8
- CVE-2016-10266LibTIFF 4.0.7 allows remote attackers to cause a denial of s…
- CVE-2016-10267LibTIFF 4.0.7 allows remote attackers to cause a denial of s…
- CVE-2016-10268tools/tiffcp.c in LibTIFF 4.0.7 allows remote attackers to c…
Are you affected by CVE-2016-10257?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
