CVE-2016-9091
high · 7.2Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susceptible to an OS command injection vulnerability. An authenticated malicious administrator can execute arbitrary OS commands with elevated system privileges.
7.2
CVSS
10.1%
EPSS (exploit prob.)
95th
EPSS percentile
2017-04-05
Published
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| bluecoat | advanced_secure_gateway | <= 6.6.5.2 |
| bluecoat | content_analysis_system_software | <= 1.3.7.3 |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/97372
- https://bto.bluecoat.com/security-advisory/sa138
- https://www.exploit-db.com/exploits/41785/
- https://www.exploit-db.com/exploits/41786/
- http://www.securityfocus.com/bid/97372
- https://bto.bluecoat.com/security-advisory/sa138
- https://www.exploit-db.com/exploits/41785/
- https://www.exploit-db.com/exploits/41786/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2016-9091