PT-2002-2700 · Watchguard+1 · Watchguard Soho+1

Published

2002-12-31

·

Updated

2009-04-03

·

CVE-2002-1979

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WatchGuard SOHO products versions 5.1.6 and earlier Vclass/RSSA versions 3.2 SP1 and earlier
Description The issue allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server. This generates a response that contains the string, causing IPFilter to treat the response as if it were a legitimate PASV command from the server.
Recommendations For WatchGuard SOHO products versions 5.1.6 and earlier, update to a version later than 5.1.6 to resolve the issue. For Vclass/RSSA versions 3.2 SP1 and earlier, update to a version later than 3.2 SP1 to resolve the issue. As a temporary workaround, consider restricting access to the FTP server to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2002-1979

Affected Products

Vclass/Rssa
Watchguard Soho