CVE-2016-2204: Symantec Messaging Gateway

High severity, CVSS 8.2. EPSS: 0.7% chance of exploitation in the next 30 days.

The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to obtain root-shell access via crafted terminal-window input.

Affected products

  • Symantec Messaging Gateway: up to and including 10.6.0; version 10.6.0 only

Published 2016-04-22. Last modified 2026-06-17.