CVE-2012-3579
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 40%
from disclosure to weapon1 days
Published on NVDAug 29
1st PoC+1d
metasploitAug 27
exploitation probability
40%top 2% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier for remote attackers to obtain privileged access via an SSH session.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencepacketstormsecurity.com/files/116277/Symantec-Messaging-Gateway-9.5-Default-SSH-Password.htmlunverifiedexploitdbwww.exploit-db.com/exploits/21136unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/116277/Symantec-Messaging-Gateway-9.5-Default-SSH-Password.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/78034http://www.securityfocus.com/bid/55143http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120827_00