CVE-2016-10258: Broadcom Advanced Secure Gateway
Medium severity, CVSS 6.8. EPSS: 4.8% chance of exploitation in the next 30 days.
Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator user into downloading and executing malicious code.
Affected products
- Broadcom Advanced Secure Gateway: from 6.6, before 6.6.5.14 (fixed in 6.6.5.14); from 6.7, before 6.7.3.1 (fixed in 6.7.3.1)
- Broadcom Symantec Proxysg: from 6.5, before 6.5.10.8 (fixed in 6.5.10.8); from 6.6, before 6.6.5.14 (fixed in 6.6.5.14); from 6.7, before 6.7.3.1 (fixed in 6.7.3.1)
Published 2018-04-11. Last modified 2026-06-17.