SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2002-0990

The web proxy component in Symantec Enterprise Firewall (SEF) 6.5.2 through 7.0, Raptor Firewall 6.5 and 6.5.3, VelociRaptor, and Symantec Gateway Security allow remote attackers to cause a denial of service (connection resource exhaustion) via multiple…

MEDIUM 5.0EPSS 1.67%

Does this matter?

Lower severity and a low EPSS score (1.67%). Track it; it rarely justifies an emergency change on its own.

Description

The web proxy component in Symantec Enterprise Firewall (SEF) 6.5.2 through 7.0, Raptor Firewall 6.5 and 6.5.3, VelociRaptor, and Symantec Gateway Security allow remote attackers to cause a denial of service (connection resource exhaustion) via multiple connection requests to domains whose DNS server is unresponsive or does not exist, which generates a long timeout.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
1.67% probability · 76th percentile
CISA KEV
Not listed
Affected
symantec/enterprise firewall · symantec/raptor firewall · symantec/velociraptor · symantec/gateway security
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.