SB2018053020 - Authentication bypass in Symantec ASG and ProxySG
Published: May 30, 2018
Security Bulletin ID
SB2018053020
Severity
Low
Patch available
NO
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Authentication bypass (CVE-ID: CVE-2018-5241)
The vulnerability allows a remote attacker can bypass authentication on the target system.The weakness exists due to improper processing of SAML responses that contain XML nodes with comments. A remote attacker can modify a valid SAML response so that the target system will still validate the cryptographic signature and bypass SAML authentication security controls.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.