CVE-2018-18371 Details
Description
The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser. An information disclosure vulnerability in the WebFTP mode allows a malicious user to obtain plaintext authentication credentials for a remote FTP server from the ASG/ProxySG's web listing of the FTP server. Affected versions: ASG 6.6 and 6.7 prior to 6.7.4.2; ProxySG 6.5 prior to 6.5.10.15, 6.6, and 6.7 prior to 6.7.4.2.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.symantec.com/us/en/article.SYMSA1472.html | CVE | Vendor Advisory |
| https://support.symantec.com/us/en/article.SYMSA1472.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-327 | Use of a Broken or Risky Cryptographic Algorithm | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| broadcom advanced secure gateway | >= 6.7, < 6.7.4.2 6.6 |
CPE
Remediation
| |
| broadcom symantec proxysg | >= 6.5, < 6.5.10.15 >= 6.7, < 6.7.4.2 6.6 |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jul 8, 2021 | CPE Deprecation Remap | [email protected] |
| Jul 8, 2021 | CPE Deprecation Remap | [email protected] |
| Jun 24, 2021 | CPE Deprecation Remap | [email protected] |
| Jun 24, 2021 | CPE Deprecation Remap | [email protected] |
| Jun 24, 2021 | CPE Deprecation Remap | [email protected] |
| Aug 24, 2020 | CWE Remap | [email protected] |
| Sep 5, 2019 | Initial Analysis | [email protected] |