Lucene search

K
cveSymantecCVE-2023-23955
HistoryJun 01, 2023 - 1:15 a.m.

CVE-2023-23955

2023-06-0101:15:17
CWE-918
symantec
web.nvd.nist.gov
24
cve-2023-23955
advanced secure gateway
content analysis
ssrf
vulnerability

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

AI Score

8

Confidence

High

EPSS

0.001

Percentile

24.2%

Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-Side Request Forgery vulnerability.

Affected configurations

Nvd
Node
broadcomadvanced_secure_gatewayRange<7.3.13.1
OR
broadcomcontent_analysisRange<3.1.6.0
VendorProductVersionCPE
broadcomadvanced_secure_gateway*cpe:2.3:a:broadcom:advanced_secure_gateway:*:*:*:*:*:*:*:*
broadcomcontent_analysis*cpe:2.3:a:broadcom:content_analysis:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Advanced Secure Gateway, Content Analysis",
    "versions": [
      {
        "version": "7.3.13.1, 3.1.6..0",
        "status": "affected"
      }
    ]
  }
]

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

AI Score

8

Confidence

High

EPSS

0.001

Percentile

24.2%

Related for CVE-2023-23955