Lucene search

K
cve[email protected]CVE-2001-0183
HistoryMay 07, 2001 - 4:00 a.m.

CVE-2001-0183

2001-05-0704:00:00
web.nvd.nist.gov
65
cve-2001-0183
freebsd 4.2
ipfw
ip6fw
ece flag
tcp packet
access restriction
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.7 Medium

AI Score

Confidence

Low

0.027 Low

EPSS

Percentile

90.4%

ipfw and ip6fw in FreeBSD 4.2 and earlier allows remote attackers to bypass access restrictions by setting the ECE flag in a TCP packet, which makes the packet appear to be part of an established connection.

Affected configurations

NVD
Node
freebsdfreebsdMatch3.0
OR
freebsdfreebsdMatch3.1
OR
freebsdfreebsdMatch3.3
OR
freebsdfreebsdMatch3.4
OR
freebsdfreebsdMatch3.5
OR
freebsdfreebsdMatch3.5.1
OR
freebsdfreebsdMatch4.0
OR
freebsdfreebsdMatch4.0alpha
OR
freebsdfreebsdMatch4.1
OR
freebsdfreebsdMatch4.1.1
OR
freebsdfreebsdMatch4.2

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.7 Medium

AI Score

Confidence

Low

0.027 Low

EPSS

Percentile

90.4%

Related for CVE-2001-0183