The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discover an encrypted AD password by leveraging certain read privileges.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160418_00 | vendor advisory |
http://packetstormsecurity.com/files/136758/Symantec-Brightmail-10.6.0-7-LDAP-Credential-Grabber.html | exploit vdb entry third party advisory |
http://www.securityfocus.com/bid/86137 | exploit vdb entry third party advisory |
http://www.securitytracker.com/id/1035609 | vdb entry third party advisory |
https://www.exploit-db.com/exploits/39715/ | exploit vdb entry third party advisory |