CVE-2013-4672: Symantec Web Gateway
High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.
The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 has an incorrect sudoers file, which allows local users to bypass intended access restrictions via a command.
Affected products
- Symantec Web Gateway: up to and including 5.1; version 5.0 only; version 5.0.1 only; version 5.0.2 only; version 5.0.3 only; version 5.0.3.18 only
- Symantec Web Gateway Appliance 8450
- Symantec Web Gateway Appliance 8490
Published 2013-08-01. Last modified 2026-06-16.