Top Layer Attack Mitigator IPS 5500 Denial Of Service Vulnerability
BID:11049
Info
Top Layer Attack Mitigator IPS 5500 Denial Of Service Vulnerability
| Bugtraq ID: | 11049 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 25 2004 12:00AM |
| Updated: | Aug 25 2004 12:00AM |
| Credit: | Mazin Faour, Louis Garman of IRM Security are credited for this vulnerability. |
| Vulnerable: |
TopLayer Attack Mitigator 5500 3.11 .008 |
| Not Vulnerable: |
TopLayer Attack Mitigator 5500 3.11 .014 |
Discussion
Top Layer Attack Mitigator IPS 5500 Denial Of Service Vulnerability
The Attack Mitigator IPS 5500 is reportedly susceptible to a denial of service vulnerability.
This vulnerability presents itself when the device is bombarded with a very high volume of HTTP traffic.
The vendor reports that in certain configurations, it is possible for the devices overload protection feature to incorrectly activate, causing a denial of service condition. Once this condition has occurred, the device is reportedly unable to process HTTP traffic.
The IPS 5500 with firmware versions prior to 3.11.014 are reported susceptible to this vulnerability.
The Attack Mitigator IPS 5500 is reportedly susceptible to a denial of service vulnerability.
This vulnerability presents itself when the device is bombarded with a very high volume of HTTP traffic.
The vendor reports that in certain configurations, it is possible for the devices overload protection feature to incorrectly activate, causing a denial of service condition. Once this condition has occurred, the device is reportedly unable to process HTTP traffic.
The IPS 5500 with firmware versions prior to 3.11.014 are reported susceptible to this vulnerability.
Exploit / POC
Top Layer Attack Mitigator IPS 5500 Denial Of Service Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Top Layer Attack Mitigator IPS 5500 Denial Of Service Vulnerability
Solution:
The vendor has released firmware version 3.11.014 for affected devices. Users of affected devices should contact the vendor for further information on obtaining fixes.
Solution:
The vendor has released firmware version 3.11.014 for affected devices. Users of affected devices should contact the vendor for further information on obtaining fixes.
References
Top Layer Attack Mitigator IPS 5500 Denial Of Service Vulnerability
References:
References:
- Attack Mitigator IPS Product Page (Top Layer)
- IRM 010: Top Layer Attack Mitigator IPS 5500 Denial of Service ("Advisories"
)