CVE-2002-0990
The web proxy component in Symantec Enterprise Firewall (SEF) 6.5.2 through 7.0, Raptor Firewall 6.5 and 6.5.3, VelociRaptor, and Symantec Gateway Security allow remote attackers to cause a denial of service (connection resource exhaustion) via multiple…
Does this matter?
Lower severity and a low EPSS score (1.67%). Track it; it rarely justifies an emergency change on its own.
Description
The web proxy component in Symantec Enterprise Firewall (SEF) 6.5.2 through 7.0, Raptor Firewall 6.5 and 6.5.3, VelociRaptor, and Symantec Gateway Security allow remote attackers to cause a denial of service (connection resource exhaustion) via multiple connection requests to domains whose DNS server is unresponsive or does not exist, which generates a long timeout.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 1.67% probability · 76th percentile
- CISA KEV
- Not listed
- Affected
- symantec/enterprise firewall · symantec/raptor firewall · symantec/velociraptor · symantec/gateway security
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=103463869503124&w=2
- http://securityresponse.symantec.com/avcenter/security/Content/2002.10.11.htmlPatch, Vendor Advisory
- http://www.iss.net/security_center/static/10364.phpVendor Advisory
- http://www.securityfocus.com/bid/5958
- http://marc.info/?l=bugtraq&m=103463869503124&w=2
- http://securityresponse.symantec.com/avcenter/security/Content/2002.10.11.htmlPatch, Vendor Advisory
- http://www.iss.net/security_center/static/10364.phpVendor Advisory
- http://www.securityfocus.com/bid/5958
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.