CVE-2016-9097: Broadcom Advanced Secure Gateway

High severity, CVSS 7.2. EPSS: 2.4% chance of exploitation in the next 30 days.

The Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.8, ProxySG 6.5 prior 6.5.10.6, ProxySG 6.6 prior to 6.6.5.8, and ProxySG 6.7 prior to 6.7.1.2 management consoles do not, under certain circumstances, correctly authorize administrator users. A malicious administrator with read-only access can exploit this vulnerability to access management console functionality that requires read-write access privileges.

Affected products

  • Broadcom Advanced Secure Gateway: version 6.6 only; version 6.6.3 only; version 6.6.4 only; version 6.6.4.3 only; version 6.6.5.1 only
  • Broadcom Symantec Proxysg: version 6.5 only; version 6.5.1 only; version 6.5.2 only; version 6.5.2.10 only; version 6.5.4.1 only; version 6.5.5.7 only; …

Published 2017-05-11. Last modified 2026-06-17.