PT-2022-3498 · Symantec · Symantec Advanced Secure Gateway+1

Published

2022-07-07

·

Updated

2023-08-08

·

CVE-2021-46825

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Symantec Advanced Secure Gateway (ASG) and ProxySG (affected versions not specified)
Description The issue is related to an HTTP desync vulnerability. When a remote unauthenticated attacker and other web clients communicate through the proxy with the same web server, the attacker can send crafted HTTP requests and cause the proxy to forward web server responses to unintended clients. This can be exploited by a remote attacker to perform an HTTP request smuggling attack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

BDU:2022-04279
CVE-2021-46825

Affected Products

Proxysg
Symantec Advanced Secure Gateway