peter bassill · operator
$ cve CVE-2013-1616 JSON

CVE-2013-1616 EXPLOIT

8.3
HIGH · CVSS 2.0 · EPSS 10.7% (pctl 96)

Patch early

A public exploit exists.

Description

The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote attackers to execute arbitrary commands by injecting a command into an application script.

Scoring

CVSS8.3 (HIGH, v2.0)
VectorAV:A/AC:L/Au:N/C:C/I:C/A:C
EPSS10.75% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2013-08-01
Last modified2026-06-16

Affected (3)

VendorProduct
symantecweb gateway
symantecweb gateway appliance 8450
symantecweb gateway appliance 8490

Public exploits

SourceTitleDate
exploit-dbSymantec Web Gateway 5.1.0.x - Multiple Vulnerabilities2013-07-27

References

→ the Explorer  ·  watch your stack  ·  NVD