CVE-2002-0309
SMTP proxy in Symantec Enterprise Firewall (SEF) 6.5.x includes the firewall's physical interface name and address in an SMTP protocol exchange when NAT translation is made to an address other than the firewall, which could allow remote attackers to…
Does this matter?
Lower severity and a low EPSS score (1.66%). Track it; it rarely justifies an emergency change on its own.
Description
SMTP proxy in Symantec Enterprise Firewall (SEF) 6.5.x includes the firewall's physical interface name and address in an SMTP protocol exchange when NAT translation is made to an address other than the firewall, which could allow remote attackers to determine certain firewall configuration information.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.66% probability · 75th percentile
- CISA KEV
- Not listed
- Affected
- symantec/enterprise firewall
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=101424307617060&w=2
- http://marc.info/?l=bugtraq&m=101430810813853&w=2
- http://securityresponse.symantec.com/avcenter/security/Content/2002.02.20.html
- http://www.iss.net/security_center/static/8251.php
- http://www.securityfocus.com/bid/4141
- http://marc.info/?l=bugtraq&m=101424307617060&w=2
- http://marc.info/?l=bugtraq&m=101430810813853&w=2
- http://securityresponse.symantec.com/avcenter/security/Content/2002.02.20.html
- http://www.iss.net/security_center/static/8251.php
- http://www.securityfocus.com/bid/4141
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.