VulnerabilityModified
CVE-2002-1535
Secure Webserver 1.1 in Raptor 6.5 and Symantec Enterprise Firewall 6.5.2 allows remote attackers to identify IP addresses of hosts on the internal network via a CONNECT request, which generates different error messages if the host is present.
MEDIUM 5.0EPSS 2.45%
Does this matter?
Lower severity and a low EPSS score (2.45%). Track it; it rarely justifies an emergency change on its own.
Description
Secure Webserver 1.1 in Raptor 6.5 and Symantec Enterprise Firewall 6.5.2 allows remote attackers to identify IP addresses of hosts on the internal network via a CONNECT request, which generates different error messages if the host is present.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.45% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- symantec/enterprise firewall · symantec/raptor firewall
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0190.htmlPatch, Vendor Advisory
- http://securityresponse.symantec.com/avcenter/security/Content/2002.10.11a.html
- http://www.iss.net/security_center/static/10363.php
- http://www.securityfocus.com/bid/5959Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0190.htmlPatch, Vendor Advisory
- http://securityresponse.symantec.com/avcenter/security/Content/2002.10.11a.html
- http://www.iss.net/security_center/static/10363.php
- http://www.securityfocus.com/bid/5959Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.