CVE-2012-0298 describes a critical vulnerability in Symantec Web Gateway 5.0.x before 5.0.3, where file-management scripts in the management GUI allow remote attackers to read or delete arbitrary files. With a CVSS score of 6.4 (AV:N/AC:L/Au:N/C:P/I:N/A:P) and a FAUCET Risk Score of 90/100, this flaw is easily exploitable over the network without authentication, potentially leading to unauthorized information disclosure and data destruction. While not listed on the KEV catalog and lacking Metasploit or Nuclei modules, a public exploit (EDB-19406) exists, yet there is minimal community discussion or media coverage surrounding this decade-old vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0CPE matchmatch criteria | cpe:2.3:a:symantec:web_gateway:5.0:*:*:*:*:*:*:* | ||
5.0.1CPE matchmatch criteria | cpe:2.3:a:symantec:web_gateway:5.0.1:*:*:*:*:*:*:* | ||
5.0.2CPE matchmatch criteria | cpe:2.3:a:symantec:web_gateway:5.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] Symantec Web Gateway (SWG) Multiple Vulnerabilities #1
May 17, 2012[R1] Symantec Web Gateway (SWG) Multiple Vulnerabilities #1
May 17, 2012[R1] Symantec Web Gateway (SWG) Multiple Vulnerabilities #1
May 17, 2012