peter bassill · operator
$ cve CVE-2012-2977 JSON

CVE-2012-2977 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 2.8% (pctl 86)

Patch early

A public exploit exists.

Description

The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwords via crafted input to an application script.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS2.78% — more likely to be exploited than 86% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2012-07-23
Last modified2026-06-16

Affected (1)

VendorProduct
symantecweb gateway

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD