Lucene search

K
nvd[email protected]NVD:CVE-2001-1101
HistorySep 08, 2001 - 4:00 a.m.

CVE-2001-1101

2001-09-0804:00:00
web.nvd.nist.gov
2

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

AI Score

6.3

Confidence

High

EPSS

0.002

Percentile

55.3%

The Log Viewer function in the Check Point FireWall-1 GUI for Solaris 3.0b through 4.1 SP2 does not check for the existence of ‘.log’ files when saving files, which allows (1) remote authenticated users to overwrite arbitrary files ending in ‘.log’, or (2) local users to overwrite arbitrary files via a symlink attack.

Affected configurations

Nvd
Node
checkpointfirewall-1Match3.0
OR
checkpointfirewall-1Match4.0
OR
checkpointfirewall-1Match4.1
OR
checkpointfirewall-1Match4.1sp1
OR
checkpointfirewall-1Match4.1sp2
VendorProductVersionCPE
checkpointfirewall-13.0cpe:2.3:a:checkpoint:firewall-1:3.0:*:*:*:*:*:*:*
checkpointfirewall-14.0cpe:2.3:a:checkpoint:firewall-1:4.0:*:*:*:*:*:*:*
checkpointfirewall-14.1cpe:2.3:a:checkpoint:firewall-1:4.1:*:*:*:*:*:*:*
checkpointfirewall-14.1cpe:2.3:a:checkpoint:firewall-1:4.1:sp1:*:*:*:*:*:*
checkpointfirewall-14.1cpe:2.3:a:checkpoint:firewall-1:4.1:sp2:*:*:*:*:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

AI Score

6.3

Confidence

High

EPSS

0.002

Percentile

55.3%

Related for NVD:CVE-2001-1101