CVE-2016-2203
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discover an encrypted AD password by leveraging certain read privileges.
- Affected products
- Symantec Messaging Gateway
- Symantec Messaging Gateway
- = 10.6.0
- Fix
- Available
- CVSS 3.0
- 7.8 HIGH
- EPSS
- 7.1% (94th percentile)
- Weakness
- CWE-255
- NVD status
- Modified
- Published
- 2016-04-22
CVE-2016-2203 at NVD
6 known exploits for CVE-2016-2203
Proof-of-concept code and exploit modules indexed by Sploitus
Symantec Messaging Gateway 10 Exposure Of Stored AD Password
Symantec Brightmail 10.6.0-7 - LDAP Credentials Disclosure (Metasploit)
Symantec Brightmail 10.6.0-7 - LDAP Credentials Disclosure (Metasploit)
Symantec Brightmail 10.6.0-7 - LDAP Credentials Disclosure (Metasploit)
Symantec Brightmail 10.6.0-7 LDAP Credential Grabber
Symantec Messaging Gateway 10 Exposure of Stored AD Password Vulnerability