← Vulnerability feed

Vulnerability record · CVE-2017-6328 · published 11 August 2017

CVE-2017-6328: Symantec message gateway cross-site request forgery vulnerability

Symantec · Message Gateway

The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbreviated as CSRF or XSRF), which is a type of malicious exploit of a website where unauthorized commands are transmitted from a user that the web application trusts. A CSRF attack attempts to exploit the trust that a specific website has in a user's browser.

8.8 CVSS 3.0 High EPSS 2.1% · top 18.7% CWE-352 · Cross-site request forgery
8.8CVSS 3.0 base score, v2 6.8
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbreviated as CSRF or XSRF), which is a type of malicious exploit of a website where unauthorized commands are transmitted from a user that the web application trusts. A CSRF attack attempts to exploit the trust that a specific website has in a user's browser.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-6328 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2017-6327Symantec Messaging Gateway command injection enables remote code executionSymantec Messaging Gateway before 10.6.3-267 is affected by a command injection flaw that allows remote code execution. An attacker who can reach the…KEVEPSS 36%analysed9.8CVE-2019-12751Symantec message gateway vulnerabilitySymantec Messaging Gateway, prior to 10.7.1, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker…EPSS 2.3%9.8CVE-2016-3645Symantec norton security vulnerabilityInteger overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:…EPSS 25%8.4CVE-2016-3646Symantec norton security improper input validation vulnerabilityThe AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syma…EPSS 18%8.4CVE-2016-3644Symantec norton security improper input validation vulnerabilityThe AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syma…EPSS 18%8.4CVE-2016-2207Symantec mail security for microsoft exchange improper input validation vulnerabilityThe AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syma…EPSS 18%7.8CVE-2016-2211Symantec AntiVirus Decomposer CAB parsing memory corruptionThe AntiVirus Decomposer engine in numerous Symantec and Norton products mishandles crafted CAB files during decompression, causing a memory buffer o…EPSS 53%analysed7.3CVE-2016-2210Symantec mail security for microsoft exchange memory buffer overflow vulnerabilityBuffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server …EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2017-6328), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.