PT-2012-2479 · Symantec · Symantec Message Filter+1
Published
2012-07-05
·
Updated
2012-07-06
·
CVE-2012-0303
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Symantec Message Filter version 6.3
Description
The issue concerns multiple cross-site request forgery (CSRF) vulnerabilities in the Brightmail Control Center component. These vulnerabilities allow remote attackers to hijack the authentication of arbitrary users, enabling them to execute application commands or create admin accounts.
Recommendations
For Symantec Message Filter version 6.3, consider disabling access to the Brightmail Control Center until a patch is available to prevent potential exploitation of the CSRF vulnerabilities. Restrict access to admin account creation and application command execution to minimize the risk of unauthorized actions.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Brightmail Control Center
Symantec Message Filter