PT-2002-3109 · Sygate · Sygate Personal Firewall
Publicado
2002-12-31
·
Atualizado
2008-09-05
·
CVE-2002-2397
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Sygate personal firewall version 5.0
Description
The issue allows remote attackers to bypass firewall filters. This can be achieved by spoofing either the source IP address as 127.0.0.1 or the network address as 127.0.0.0.
Recommendations
For Sygate personal firewall version 5.0, consider restricting access to the firewall configuration to prevent unauthorized changes until a patch is available. As a temporary workaround, monitor network traffic closely for signs of spoofed IP addresses, specifically 127.0.0.1 and 127.0.0.0, to minimize the risk of exploitation.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sygate Personal Firewall