CVE-2016-9100: Broadcom Advanced Secure Gateway

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.13, ASG 6.7 prior to 6.7.3.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6 prior to 6.6.5.13, and ProxySG 6.7 prior to 6.7.3.1 are susceptible to an information disclosure vulnerability. An attacker with local access to the client host of an authenticated administrator user can, under certain circumstances, obtain sensitive authentication credential information.

Affected products

  • Broadcom Advanced Secure Gateway: from 6.6, before 6.6.5.13 (fixed in 6.6.5.13); from 6.7, before 6.7.3.1 (fixed in 6.7.3.1)
  • Broadcom Symantec Proxysg: from 6.5, before 6.5.10.6 (fixed in 6.5.10.6); from 6.6, before 6.6.5.13 (fixed in 6.6.5.13); from 6.7, before 6.7.3.1 (fixed in 6.7.3.1)

Published 2017-05-11. Last modified 2026-06-17.