CVE-2004-1473
Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 allow remote attackers to bypass filtering and determine whether the device is running…
Does this matter?
Lower severity and a low EPSS score (3.94%). Track it; it rarely justifies an emergency change on its own.
Description
Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 allow remote attackers to bypass filtering and determine whether the device is running services such as tftpd, snmpd, or isakmp via a UDP port scan with a source port of UDP 53.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 3.94% probability · 90th percentile
- CISA KEV
- Not listed
- Affected
- symantec/firewall vpn appliance 100 · symantec/firewall vpn appliance 200 · symantec/firewall vpn appliance 200r · symantec/gateway security 320 · symantec/gateway security 360 · symantec/gateway security 360r · symantec/nexland isb soho firewall appliance · symantec/nexland pro100 firewall appliance · symantec/nexland pro400 firewall appliance · symantec/nexland pro800 firewall appliance · symantec/nexland pro800turbo firewall appliance · symantec/nexland wavebase firewall appliance
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=109588376426070&w=2
- http://secunia.com/advisories/12635
- http://securityresponse.symantec.com/avcenter/security/Content/2004.09.22.htmlPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/329230Patch, Third Party Advisory, US Government Resource
- http://www.osvdb.org/10205
- http://www.securityfocus.com/bid/11237
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17470
- http://marc.info/?l=bugtraq&m=109588376426070&w=2
- http://secunia.com/advisories/12635
- http://securityresponse.symantec.com/avcenter/security/Content/2004.09.22.htmlPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/329230Patch, Third Party Advisory, US Government Resource
- http://www.osvdb.org/10205
- http://www.securityfocus.com/bid/11237
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17470
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.