Symantec Messaging Gateway
Vendor:
First CVE: Apr 7, 2014 · Active for 12 years
6
Total CVEs
More Total CVEs than 83% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 51% of tracked products
16.7%
KEV Rate
Higher KEV Rate than 99% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Symantec Messaging Gateway over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 7, 2014
12 years ago
Most Recent CVE
Jan 26, 2024
914 days ago
CVE Severity & Scoring
Symantec Messaging Gateway6 CVEs
33%
33%
33%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High3 (50.0%)
None3 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0160HIGH The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive inform | Apr 7, 2014 | 7.5 | 99 | YES | YES |
CVE-2024-23615CRITICAL A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code ex | Jan 26, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-23614CRITICAL A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code exe | Jan 26, 2024 | 9.8 | 24 | NO | NO |
CVE-2021-30651MEDIUM A malicious authenticated SMG administrator user can obtain passwords for external LDAP/Active Directory servers that they might not otherwise be authorized to access. | Jun 24, 2022 | 4.9 | 19 | NO | NO |
CVE-2020-12594HIGH A privilege escalation flaw allows a malicious, authenticated, privileged CLI user to escalate their privileges on the system and gain full control over the SMG appliance. This aff | Dec 10, 2020 | 7.2 | 19 | NO | NO |
CVE-2020-12595MEDIUM An information disclosure flaw allows a malicious, authenticated, privileged web UI user to obtain a password for a remote SCP backup server that they might not otherwise be author | Dec 10, 2020 | 4.9 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
1 CVE
16.7% of CVEs· 99th percentile
Metasploit
1 CVE
16.7% of CVEs· 98th percentile
Nuclei
1 CVE
16.7% of CVEs· 98th percentile
ExploitDB
1 CVE
16.7% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Symantec Messaging Gateway
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 10.6.1 | 1 | 7.5 | 100.0% | 1 | 1 |
| 10.6.0 | 1 | 7.5 | 100.0% | 1 | 1 |