CVE-2006-2341
The HTTP proxy in Symantec Gateway Security 5000 Series 2.0.1 and 3.0, and Enterprise Firewall 8.0, when NAT is being used, allows remote attackers to determine internal IP addresses by using malformed HTTP requests, as demonstrated using a get request…
Does this matter?
Lower severity and a low EPSS score (3.79%). Track it; it rarely justifies an emergency change on its own.
Description
The HTTP proxy in Symantec Gateway Security 5000 Series 2.0.1 and 3.0, and Enterprise Firewall 8.0, when NAT is being used, allows remote attackers to determine internal IP addresses by using malformed HTTP requests, as demonstrated using a get request without a space separating the URI.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 3.79% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- symantec/enterprise firewall · symantec/gateway security
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/20082Patch, Vendor Advisory
- http://securityresponse.symantec.com/avcenter/security/Content/2006.05.10.htmlPatch, Vendor Advisory
- http://securitytracker.com/id?1016057Patch
- http://securitytracker.com/id?1016058Patch
- http://www.securityfocus.com/archive/1/433876/30/5040/threaded
- http://www.securityfocus.com/bid/17936Exploit
- http://www.vupen.com/english/advisories/2006/1764Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26370
- http://secunia.com/advisories/20082Patch, Vendor Advisory
- http://securityresponse.symantec.com/avcenter/security/Content/2006.05.10.htmlPatch, Vendor Advisory
- http://securitytracker.com/id?1016057Patch
- http://securitytracker.com/id?1016058Patch
- http://www.securityfocus.com/archive/1/433876/30/5040/threaded
- http://www.securityfocus.com/bid/17936Exploit
- http://www.vupen.com/english/advisories/2006/1764Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26370
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.