CVE-2016-2203: Symantec Messaging Gateway

High severity, CVSS 7.8. EPSS: 7.1% chance of exploitation in the next 30 days.

The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discover an encrypted AD password by leveraging certain read privileges.

Affected products

  • Symantec Messaging Gateway: version 10.6.0 only

Published 2016-04-22. Last modified 2026-06-17.