CVE-2019-18375: Broadcom Advanced Secure Gateway
Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.
The ASG and ProxySG management consoles are susceptible to a session hijacking vulnerability. A remote attacker, with access to the appliance management interface, can hijack the session of a currently logged-in user and access the management console.
Affected products
- Broadcom Advanced Secure Gateway: from 6.7.4, before 6.7.4.10 (fixed in 6.7.4.10); from 7.1, before 7.2.0.1 (fixed in 7.2.0.1)
- Broadcom Symantec Proxysg: from 6.7.4, before 6.7.4.10 (fixed in 6.7.4.10); from 7.1, before 7.2.0.1 (fixed in 7.2.0.1)
Published 2020-04-10. Last modified 2026-06-17.