Symantec Messaging Gateway

Vendor:

First CVE: Apr 7, 2014 · Active for 12 years

6
Total CVEs
More Total CVEs than 83% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 51% of tracked products
16.7%
KEV Rate
Higher KEV Rate than 99% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Symantec Messaging Gateway over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 7, 2014
12 years ago
Most Recent CVE
Jan 26, 2024
914 days ago

CVE Severity & Scoring

Symantec Messaging Gateway6 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High3 (50.0%)
None3 (50.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive inform
Apr 7, 20147.599YESYES
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code ex
Jan 26, 20249.827NONO
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code exe
Jan 26, 20249.824NONO
A malicious authenticated SMG administrator user can obtain passwords for external LDAP/Active Directory servers that they might not otherwise be authorized to access.
Jun 24, 20224.919NONO
A privilege escalation flaw allows a malicious, authenticated, privileged CLI user to escalate their privileges on the system and gain full control over the SMG appliance. This aff
Dec 10, 20207.219NONO
An information disclosure flaw allows a malicious, authenticated, privileged web UI user to obtain a password for a remote SCP backup server that they might not otherwise be author
Dec 10, 20204.915NONO

Exploit Exposure

Signals from CVEs in this product scope (6 CVEs).

CISA KEV
1 CVE
16.7% of CVEs· 99th percentile
Metasploit
1 CVE
16.7% of CVEs· 98th percentile
Nuclei
1 CVE
16.7% of CVEs· 98th percentile
ExploitDB
1 CVE
16.7% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (6 CVEs).

Media Mentions

Signals from CVEs in this product scope (6 CVEs).

Top CNAs Publishing CVEs For Symantec Messaging Gateway

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
10.6.117.5100.0%11
10.6.017.5100.0%11