Messaging Gateway (SMG) - Vulnerability Assessment for CVE-2026-46300
search cancel

Messaging Gateway (SMG) - Vulnerability Assessment for CVE-2026-46300

book

Article ID: 448684

calendar_today

Updated On:

Products

Messaging Gateway

Issue/Introduction

Is Symantec Messaging Gateway (SMG) vulnerable to CVE-2026-46300?

Broadcom has received inquiries regarding a potential vulnerability (CVE-2026-46300) that could allow for unauthorized code execution. This article provides the current assessment and impact for SMG customers.

Environment

Version: 10.9.2 and later

Resolution

Broadcom engineering has confirmed that Symantec Messaging Gateway is not vulnerable to CVE-2026-46300 in the product's shipped configuration.

Technical Assessment

The vulnerability is considered unexploitable on the SMG appliance due to the following security controls:

  • Restricted Shell: SMG utilizes a restricted command-line interface (CLI) that prevents 'normal' shell access. This environment does not allow for the uploading of source code, building of executables, or the execution of unauthorized binaries required for this exploit.
  • Appliance Hardening: The appliance architecture is specifically hardened to restrict process execution to only authorized Symantec services.

Future Mitigation

While the current version is not vulnerable, Broadcom will update the SMG kernel in the upcoming version 10.9.3 release. This proactive update is intended to address theoretical findings and ensure the product remains clear of future security scan flags related to this CVE.

Additional Information