← Vulnerability feed

Vulnerability record · CVE-2014-7285 · published 17 December 2014

CVE-2014-7285: Symantec Web Gateway management console OS command injection

Symantec · Web Gateway

The management console of the Symantec Web Gateway appliance before 5.2.2 passes attacker-controlled input into unspecified PHP scripts without sanitizing it, allowing OS command injection. An attacker who can authenticate to the console can run arbitrary commands on the appliance, which is a security control point for outbound web traffic.

6.5 CVSS 2.0 Medium EPSS 50% · top 1.1% CWE-77 · Command injection
6.5CVSS 2.0 base score
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
17 Jun 2026Last modified by NVD

Description

The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts.

AV:N/AC:L/Au:S/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote authenticated OS command injection on a security appliance with public exploit code and very high EPSS, though it requires valid console credentials.

What it is

The management console of the Symantec Web Gateway appliance before 5.2.2 passes attacker-controlled input into unspecified PHP scripts without sanitizing it, allowing OS command injection. An attacker who can authenticate to the console can run arbitrary commands on the appliance, which is a security control point for outbound web traffic.

Impact

An authenticated attacker gains arbitrary OS command execution on the SWG appliance, enabling full compromise of the device and any data or credentials it handles.

Attack surface

Reached remotely over the network through the management console's PHP scripts; the CVSS vector (AV:N/AC:L/Au:S) indicates network access with low complexity but requires a valid authenticated session. No user interaction is indicated.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but public exploit code exists (Exploit-DB 36263, Packet Storm) and EPSS is 0.503 (98.9th percentile), indicating meaningful likelihood of exploitation.

What to do

  • Upgrade Symantec Web Gateway to 5.2.2 or later per the vendor advisory.
  • Restrict management console access to a dedicated administrative network and block it from untrusted networks.
  • Enforce strong unique credentials and least privilege for console accounts; audit and remove unused accounts.
  • Monitor the appliance for unexpected outbound connections or process execution that would indicate post-exploitation activity.

Detection

  • Review management console and web server logs for requests to PHP scripts containing shell metacharacters or command strings.
  • Alert on unexpected child processes or shell execution spawned by the web server/PHP process on the appliance.
  • Monitor for anomalous outbound traffic or new listening services originating from the SWG appliance.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-7285 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-2953Symantec Web Gateway management console OS command injectionThe management console in Symantec Web Gateway 5.0.x before 5.0.3.18 fails to properly sanitize input passed to application scripts, allowing OS comm…EPSS 67%analysed10.0CVE-2012-2976Symantec web gateway os command injection vulnerabilityThe management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary shell commands via crafted input to…EPSS 5.4%10.0CVE-2012-0297Symantec Web Gateway management GUI access control flaw enables remote code executionThe management GUI in Symantec Web Gateway 5.0.x before 5.0.3 fails to properly restrict access to application scripts. Remote attackers can inject o…EPSS 73%analysed10.0CVE-2012-0299Symantec Web Gateway GUI file-management scripts allow arbitrary code uploadThe file-management scripts in the management GUI of Symantec Web Gateway 5.0.x before 5.0.3 permit remote attackers to upload arbitrary code to a de…EPSS 64%analysed9.8CVE-2013-5017Symantec web gateway vulnerabilitySNMPConfig.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remote attackers to execute arbitrary commands via unspeci…EPSS 7.0%8.8CVE-2016-5313Symantec web gateway os command injection vulnerabilitySymantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users to execute arbitrary OS commands.EPSS 4.6%8.5CVE-2015-5690Symantec web gateway os command injection vulnerabilityThe management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to bypass …EPSS 3.5%8.3CVE-2015-6547Symantec web gateway command injection vulnerabilityThe management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute…EPSS 4.3%

Source: NIST National Vulnerability Database (record CVE-2014-7285), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.