Symantec VIP Enterprise Gateway vulnerability information regarding potential pen test vulnerability detections
search cancel

Symantec VIP Enterprise Gateway vulnerability information regarding potential pen test vulnerability detections

book

Article ID: 418198

calendar_today

Updated On:

Products

VIP Service

Issue/Introduction

Pen and testing may detect potential vulnerabilities in Symantec VIP Enterprise Gateway (EG) 9.11.x. This article is a collection of reported vulnerabilities and recommended actions. 

Environment

Product: Symantec VIP Enterprise Gateway

Resolution

CWE-548 - Directory Listing Vulnerability

  • Status: The VIP EG is an internal application typically protected by the DMG and other safeguards. This is a low-priority vulnerability.
  • Action: This is addressed in VIP EGW version 9.11.3 and higher. 

CWE-548 - Directory Listing Vulnerability

  • Status: The VIP EG is an internal application typically protected by the DMG and other safeguards. This is a low-priority vulnerability.
  • Action: This is addressed in VIP EGW version 9.11.3 and higher. 

CVE-2025-15467, CVSS 9.8 - OpenSSL Version 3.0.8 and 3.6.0

  • Status: The VIP EGW does not use the OpenSSL CMS module (<openssl/cms.h>) or the PKCS7_decrypt functions, and is not susceptible to this vulnerability. 
  • Action:  OpenSLL will upgraded in VIP EGW version 9.11.3 and higher to prevent CVE detection. 

CVE-2023-38546 - Libcurl Cookie Injection Vulnerability

  • Status: VIP EG 9.11.0 does not call the curl_easy_duphandle() function or enable the cookie engine, and is not vulnerable. The libraries were upgraded in 9.11.1 and later to mitigate pen detection. 
  • Action: Upgrade to the latest version of the VIP Enterprise Gateway. 

CVE-2026-34480 - Apache Log4j Core Xml Layout Invalid XML Output

  • Status: Applications using Log4j's XmlLayout for log output are affected. Enterprise Gateway does not use Log4j's XmlLayout and is not vulnerable. 
  • Action: none required (Log4j libraries are updated in VIP EGW version 9.11.3 and higher to mitigate detection).  

CVE-2025-68161 -  Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 do not perform peer certificate TLS hostname verification

  • Status: The VIP EGW utilizes a custom UDP protocol Socket Appender for sending logs to the Syslog Server, with no TCP-based SSL/TLS encryption. There is no TCP-based SSL/TLS encryption. The VIP EGW is not vulnerable.
  • Action: none required.

CVE-2026-34477 - Apache Log4j Core TLS Hostname Verification Bypass

  • Status: This vulnerability is an incomplete fix for vulnerability (CVE-2025-68161). The VIP EGW utilizes a custom UDP protocol Socket Appender for sending logs to the Syslog Server. There is no TCP-based SSL/TLS encryption. The VIP EGW is not vulnerable.
  • Action: none required. 

CVE-2026-34478 - Apache Log4j Core CRLF Log Injection

  • Status: The VIP EGW does not use the Rfc5424Layout. The VIP EGW is not vulnerable.
  • Action: To mitigate pen test detection, this will be addressed in version 9.11.3 and higher. Strus

CVE-2025-14017 - Impacts multi-threaded LDAPS transfer

  • Status: VIP Enterprise Gateway does not use libcurl as an LDAP client. Its LDAPS connections are handled natively by Java JNDI, while the C/C++ implementation utilizes the native Windows LDAP API and the Mozilla LDAP C SDK for Linux.
  • Action: none required. (libcurl is updated to version 8.21.0 in VIP EGW version 9.11.3 and higher   to mitigate detection)

CVE-2026-6276 - Information disclosure caused by a stale custom cookie host state

  • Status: VIP Enterprise Gateway never overrides the Host header using CURLOPT_HTTPHEADER, the exact mechanical conditions required to trigger this state leak simply do not exist in the EG.
  • Action: none required. (libcurl is updated to version 8.21.0 in VIP EGW version 9.11.3 and higher to mitigate detection)

CVE-2026-6429 - credential leak with reused proxy connection

  • Status: VIP Enterprise Gateway codebase does not use .netrc files for libcurl authentication and does not configure libcurl to automatically follow HTTP redirects.
  • Action: none required. (libcurl is updated to version 8.21.0 in VIP EGW 9.11.3 version and higher to mitigate detection)

CVE-2026-7168 -  cross-proxy Digest auth state leak

  • Status: Handles across different proxies and digest authentication not met with HTTP Proxy. No functional risk. 
  • Action: none required. (libcurl is updated to version 8.21.0 in VIP EGW version 9.11.3 and higher to mitigate detection)

CVE-2025-64775 - Denial of Service

  • Status: Affected Struts versions are 2.0.0 through 6.7.0 and 7.0.0 through 7.0.3
  • Action: Struts libraries have been upgraded in  VIP EGW version 9.11.3 and higher. Upgrade to mitigate.

CVE-2025-68493 - XML External Entity Injection

  • Status: Affected Struts versions 2.0 through 6.1.0.
  • Action: Struts libraries have been upgraded in VIP EGW version 9.11.3 version and higher. Upgrade to mitigate.

CVE-2024-53677 - Apache Struts FileUploadInterceptor 

  • Status: The exploit path for this vulnerability does not exist within Symantec VIP version 9.11.2 and higher.
  • Action: Upgrade to the the latest version of the VIP EGW.

Additional Information

Broadcom recommends upgrading to the latest VIP EGW release to ensure continued compliance with security best practices.

If your 9.11.x penetration tests show vulnerabilities not listed here, open a Broadcom Support case for assistance:  Contact Broadcom Support