7.5

CVE-2007-3701

Exploit
TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) character, which might allow remote attackers to send certain network traffic and avoid detection, as demonstrated by a cmd.exe attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tippingpoint ≫ Tipping Point Version 50
Tippingpoint ≫ Tipping Point Version 200
Tippingpoint ≫ Tipping Point Version 200e
Tippingpoint ≫ Tipping Point Version 400
Tippingpoint ≫ Tipping Point Version 600e
Tippingpoint ≫ Tipping Point Version 1200
Tippingpoint ≫ Tipping Point Version 1200e
Tippingpoint ≫ Tipping Point Version 2400e
Tippingpoint ≫ Tipping Point Version 5000e
Tippingpoint ≫ Tipping Point Version sms
Tippingpoint ≫ Tipping Point Version x505
Tippingpoint ≫ Tipping Point Version x506
Tippingpoint ≫ Tipping Point Version zpha
3com ≫ Tippingpoint Ips Tos Version 2.1
3com ≫ Tippingpoint Ips Tos Version 2.1.4.6324
3com ≫ Tippingpoint Ips Tos Version 2.2
3com ≫ Tippingpoint Ips Tos Version 2.2.1
3com ≫ Tippingpoint Ips Tos Version 2.2.1.6506
3com ≫ Tippingpoint Ips Tos Version 2.2.2
3com ≫ Tippingpoint Ips Tos Version 2.2.3
3com ≫ Tippingpoint Ips Tos Version 2.2.4
3com ≫ Tippingpoint Ips Tos Version 2.5
3com ≫ Tippingpoint Ips Tos Version 2.5.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.48% 0.943
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://lists.grok.org.uk/pipermail/full-disclosure/2007-July/064550.html
http://osvdb.org/35970
http://secunia.com/advisories/26013
http://security-assessment.com/files/advisories/2007-07-11_Tippingpoint_IPS_Signature_Evasion.pdf
Patch
Vendor Advisory
Exploit
http://www.3com.com/securityalert/alerts/3COM-07-003.html
Patch
Vendor Advisory
http://www.securityfocus.com/archive/1/473311/100/0/threaded
http://www.securityfocus.com/bid/24855
Exploit
http://www.securitytracker.com/id?1018361
http://www.vupen.com/english/advisories/2007/2490
https://exchange.xforce.ibmcloud.com/vulnerabilities/35336