Lucene search

K
cve[email protected]CVE-2006-2341
HistoryMay 12, 2006 - 1:02 a.m.

CVE-2006-2341

2006-05-1201:02:00
CWE-200
web.nvd.nist.gov
21
symantec
gateway security
enterprise firewall
http proxy
vulnerability
nat
internal ip addresses
security advisory
cve-2006-2341

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.7 Medium

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.8%

The HTTP proxy in Symantec Gateway Security 5000 Series 2.0.1 and 3.0, and Enterprise Firewall 8.0, when NAT is being used, allows remote attackers to determine internal IP addresses by using malformed HTTP requests, as demonstrated using a get request without a space separating the URI.

Affected configurations

NVD
Node
symantecenterprise_firewallMatch8.0
OR
symantecgateway_securityMatch2.0.1
OR
symantecgateway_securityMatch3.0
Node
symantecgateway_securityMatch5000_series_2.0.1
OR
symantecgateway_securityMatch5000_series_3.0

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.7 Medium

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.8%

Related for CVE-2006-2341