Web Gateway
Vendor:
First CVE: Jan 14, 2011 · Active for 15 years
35
Total CVEs
More Total CVEs than 96% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Web Gateway over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 14, 2011
15 years ago
Most Recent CVE
Apr 14, 2017
3,389 days ago
CVE Severity & Scoring
Web Gateway35 CVEs
43%
51%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (5.7%)
Network2 (5.7%)
Unknown31 (88.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (11.4%)
High0 (0.0%)
Unknown31 (88.6%)
User Interaction
None2 (5.7%)
Unknown31 (88.6%)
Required2 (5.7%)
Privileges Required
Low1 (2.9%)
High0 (0.0%)
None3 (8.6%)
Unknown31 (88.6%)
Top CVEs
Signals from CVEs in this product scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-2953HIGH The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts. | Jul 23, 2012 | 10.0 | 83 | NO | YES |
CVE-2012-0297HIGH The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers to execute arbitrary code by ( | May 21, 2012 | 10.0 | 83 | NO | YES |
CVE-2012-0299HIGH The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code to a designated pathname, and possibly | May 21, 2012 | 10.0 | 81 | NO | YES |
CVE-2012-2957HIGH The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying files, related to a "file inclusion" issue. | Jul 23, 2012 | 7.2 | 65 | NO | YES |
CVE-2014-7285MEDIUM The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into | Dec 17, 2014 | 6.5 | 61 | NO | YES |
CVE-2013-1616HIGH The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote attackers to execute arbitrary commands by injecting a command into an application scr | Aug 1, 2013 | 8.3 | 41 | NO | YES |
CVE-2016-5309MEDIUM The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security | Apr 14, 2017 | 5.5 | 33 | NO | YES |
CVE-2012-2961HIGH SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vector | Jul 23, 2012 | 7.5 | 33 | NO | YES |
CVE-2012-2574HIGH SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vector | Jul 23, 2012 | 7.5 | 33 | NO | YES |
CVE-2012-4178HIGH SQL injection vulnerability in spywall/includes/deptUploads_data.php in Symantec Web Gateway 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via the groupid para | Aug 7, 2012 | 7.5 | 32 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (35 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
11.4% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
13 CVEs
37.1% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (35 CVEs).
Media Mentions
Signals from CVEs in this product scope (35 CVEs).
Top CNAs Publishing CVEs For Web Gateway
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.1 | 2 | 4.0 | 1.8% | 0 | 0 |
| 5.0.3.18 | 7 | 6.6 | 3.9% | 0 | 2 |
| 5.0.3 | 12 | 7.2 | 13.7% | 0 | 6 |
| 5.0.2 | 16 | 7.3 | 19.5% | 0 | 9 |
| 5.0.1 | 16 | 7.3 | 19.5% | 0 | 9 |
| 5.0 | 16 | 7.3 | 19.5% | 0 | 9 |
| 4.5.4.9 | 1 | 7.5 | 2.2% | 0 | 0 |
| 4.5.3.38 | 1 | 7.5 | 2.2% | 0 | 0 |
| 4.5.2.72 | 1 | 7.5 | 2.2% | 0 | 0 |
| 4.5.2.65 | 1 | 7.5 | 2.2% | 0 | 0 |
| 4.5.2.37 | 1 | 7.5 | 2.2% | 0 | 0 |
| 4.5.1.44 | 1 | 7.5 | 2.2% | 0 | 0 |
| 4.5.1.34 | 1 | 7.5 | 2.2% | 0 | 0 |
| 4.5.0.327 | 1 | 7.5 | 2.4% | 0 | 0 |
| 4.5.0.326 | 2 | 7.5 | 2.3% | 0 | 0 |
| 4.5.0.325 | 1 | 7.5 | 2.4% | 0 | 0 |
| 4.5 | 2 | 7.5 | 2.3% | 0 | 0 |