logo

Symantec Messaging Gateway SSH with backdoor user account + privilege escalation to root due to very old Kernel

ID: c08852e5-21dc-5f43-9d95-3cb0699294f5

STIX ID: report--c08852e5-21dc-5f43-9d95-3cb0699294f5

Feed Name: NCC Research

Threat Score
70/100

Date Published: 2025-12-02

Date Updated: 2026-08-01

ADMIRALTY:B6
...
...

Symantec Messaging Gateway 9.5.3-3 includes a high-risk vulnerability: an undocumented "support" SSH account with a default password ('symantec') that allows OS logins, and the appliance runs a very old Linux kernel (circa 2007) with known privilege-escalation flaws; together these could enable an attacker to obtain root access. Symantec published an update to address the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.