Vulnerability record · CVE-2018-12242 · published 19 September 2018
CVE-2018-12242: Symantec messaging gateway improper authentication vulnerability
Symantec · Messaging Gateway
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allow attackers to potentially circumvent security mechanisms currently in place and gain access to the system or network.
Description
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allow attackers to potentially circumvent security mechanisms currently in place and gain access to the system or network.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/105329 | Third Party AdvisoryVDB Entry |
| https://support.symantec.com/en_US/article.SYMSA1461.html | Vendor Advisory |
| http://www.securityfocus.com/bid/105329 | Third Party AdvisoryVDB Entry |
| https://support.symantec.com/en_US/article.SYMSA1461.html | Vendor Advisory |
Track CVE-2018-12242 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-12242), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.