7.5

CVE-2007-3701

Exploit

TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) character, which might allow remote attackers to send certain network traffic and avoid detection, as demonstrated by a cmd.exe attack.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TippingpointTipping Point Version50
TippingpointTipping Point Version200
TippingpointTipping Point Version200e
TippingpointTipping Point Version400
TippingpointTipping Point Version600e
TippingpointTipping Point Version1200
TippingpointTipping Point Version1200e
TippingpointTipping Point Version2400e
TippingpointTipping Point Version5000e
TippingpointTipping Point Versionsms
TippingpointTipping Point Versionx505
TippingpointTipping Point Versionx506
TippingpointTipping Point Versionzpha
3comTippingpoint Ips Tos Version2.1
3comTippingpoint Ips Tos Version2.1.4.6324
3comTippingpoint Ips Tos Version2.2
3comTippingpoint Ips Tos Version2.2.1
3comTippingpoint Ips Tos Version2.2.1.6506
3comTippingpoint Ips Tos Version2.2.2
3comTippingpoint Ips Tos Version2.2.3
3comTippingpoint Ips Tos Version2.2.4
3comTippingpoint Ips Tos Version2.5
3comTippingpoint Ips Tos Version2.5.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.34% 0.925
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.