CVE-2008-1095
Unspecified vulnerability in the Internet Protocol (IP) implementation in Sun Solaris 8, 9, and 10 allows remote attackers to bypass intended firewall policies or cause a denial of service (panic) via unknown vectors, possibly related to ICMP packets…
Does this matter?
Lower severity and a low EPSS score (2.30%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in the Internet Protocol (IP) implementation in Sun Solaris 8, 9, and 10 allows remote attackers to bypass intended firewall policies or cause a denial of service (panic) via unknown vectors, possibly related to ICMP packets and IP fragment reassembly.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
- EPSS
- 2.30% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- sun/solaris · sun/sunos
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/29100Vendor Advisory
- http://secunia.com/advisories/29379Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-200183-1Patch
- http://support.avaya.com/elmodocs2/security/ASA-2008-119.htm
- http://www.securityfocus.com/bid/27967Patch
- http://www.vupen.com/english/advisories/2008/0645Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40473
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5511
- http://secunia.com/advisories/29100Vendor Advisory
- http://secunia.com/advisories/29379Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-200183-1Patch
- http://support.avaya.com/elmodocs2/security/ASA-2008-119.htm
- http://www.securityfocus.com/bid/27967Patch
- http://www.vupen.com/english/advisories/2008/0645Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40473
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5511
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.