PT-2007-7000 · Ingate · Siparator+1

Publicado

2007-11-22

·

Atualizado

2008-11-15

·

CVE-2007-6098

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ingate Firewall versions prior to 4.6.0 SIParator versions prior to 4.6.0
Description The issue concerns the logging mechanism, which fails to log certain events. Specifically, it does not log truncated ICMP, UDP, and TCP packets, and it also does not log serial-console login attempts with nonexistent usernames. This lack of logging might make it easier for attackers with physical access to guess valid login credentials while avoiding detection.
Recommendations For Ingate Firewall versions prior to 4.6.0, update to version 4.6.0 or later to address the logging issue. For SIParator versions prior to 4.6.0, update to version 4.6.0 or later to address the logging issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-6098

Produtos afetados

Ingate Firewall
Siparator