LiveActive security incident?Get immediate response
CVE Record

CVE-2021-30651: A malicious authenticated SMG administrator user can obtain passwords for external LDAP/Active Directory se...

A malicious authenticated SMG administrator user can obtain passwords for external LDAP/Active Directory servers that they might not otherwise be authorized to access.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This issue affects Symantec Messaging Gateway 10.7. A logged-in SMG administrator could obtain stored passwords for external LDAP or Active Directory servers, even where they should not have separate access to those credentials.

Executive priority

Treat this as a credential-protection issue, not a broad unauthenticated compromise. Prioritize if SMG 10.7 manages directory integrations or admin access is widely shared.

Technical view

CVE-2021-30651 is a credential exposure issue in Symantec Messaging Gateway 10.7 involving external LDAP/Active Directory server passwords. The source bundle does not provide CVSS, CWE, exploit details, or specific fixed-version information.

Likely exposure

Exposure is likely limited to organizations running Symantec Messaging Gateway 10.7 with configured external LDAP or Active Directory integrations and multiple SMG administrator users.

Exploitation context

The bundle does not cite active exploitation, and KEV is false. Abuse requires authenticated SMG administrator access, so the main concern is malicious insiders or compromised SMG admin accounts.

Researcher notes

Evidence is sparse in the provided bundle. The key known facts are affected product/version, authenticated administrator prerequisite, and LDAP/AD password exposure. No exploit mechanics or confirmed fix details are provided.

Mitigation direction

  • Check Broadcom guidance for applicable SMG 10.7 remediation or upgrade direction.
  • Restrict SMG administrator access to trusted, necessary personnel only.
  • Rotate LDAP/AD bind passwords if unauthorized access cannot be ruled out.
  • Reduce LDAP/AD bind account privileges where operationally possible.

Validation and detection

  • Inventory SMG instances and confirm whether version 10.7 is present.
  • Identify SMG systems configured with external LDAP or Active Directory servers.
  • Review SMG administrator users and recent privileged access activity.
  • Confirm remediation status against Broadcom’s advisory.
  • Check LDAP/AD logs for unusual activity by SMG-related accounts.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-30651 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/aSymantec Messaging Gateway (SMG)10.7Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.