Vulnerability record · CVE-2014-7285 · published 17 December 2014
CVE-2014-7285: Symantec Web Gateway management console OS command injection
Symantec · Web Gateway
The management console of the Symantec Web Gateway appliance before 5.2.2 passes attacker-controlled input into unspecified PHP scripts without sanitizing it, allowing OS command injection. An attacker who can authenticate to the console can run arbitrary commands on the appliance, which is a security control point for outbound web traffic.
Description
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts.
AV:N/AC:L/Au:S/C:P/I:P/A:P
Automated analysis
high priorityRemote authenticated OS command injection on a security appliance with public exploit code and very high EPSS, though it requires valid console credentials.
What it is
The management console of the Symantec Web Gateway appliance before 5.2.2 passes attacker-controlled input into unspecified PHP scripts without sanitizing it, allowing OS command injection. An attacker who can authenticate to the console can run arbitrary commands on the appliance, which is a security control point for outbound web traffic.
Impact
An authenticated attacker gains arbitrary OS command execution on the SWG appliance, enabling full compromise of the device and any data or credentials it handles.
Attack surface
Reached remotely over the network through the management console's PHP scripts; the CVSS vector (AV:N/AC:L/Au:S) indicates network access with low complexity but requires a valid authenticated session. No user interaction is indicated.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but public exploit code exists (Exploit-DB 36263, Packet Storm) and EPSS is 0.503 (98.9th percentile), indicating meaningful likelihood of exploitation.
What to do
- Upgrade Symantec Web Gateway to 5.2.2 or later per the vendor advisory.
- Restrict management console access to a dedicated administrative network and block it from untrusted networks.
- Enforce strong unique credentials and least privilege for console accounts; audit and remove unused accounts.
- Monitor the appliance for unexpected outbound connections or process execution that would indicate post-exploitation activity.
Detection
- Review management console and web server logs for requests to PHP scripts containing shell metacharacters or command strings.
- Alert on unexpected child processes or shell execution spawned by the web server/PHP process on the appliance.
- Monitor for anomalous outbound traffic or new listening services originating from the SWG appliance.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-7285 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-7285), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.