Symantec Enterprise Firewall/VPN Appliance Multiple Remote Vulnerabilities
BID:11237
Info
Symantec Enterprise Firewall/VPN Appliance Multiple Remote Vulnerabilities
| Bugtraq ID: | 11237 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2004 12:00AM |
| Updated: | Sep 22 2004 12:00AM |
| Credit: | Discovery is credited to Mike Sues and the Rigel Kent. |
| Vulnerable: |
Symantec Nexland WaveBase Firewall Appliance Symantec Nexland Pro800turbo Firewall Appliance Symantec Nexland Pro800 Firewall Appliance Symantec Nexland Pro400 Firewall Appliance Symantec Nexland Pro100 Firewall Appliance Symantec Nexland ISB SOHO Firewall Appliance Symantec Gateway Security 360R Symantec Gateway Security 360 Symantec Gateway Security 320 Symantec Firewall/VPN Appliance 200R Symantec Firewall/VPN Appliance 200 Symantec Firewall/VPN Appliance 100 |
| Not Vulnerable: | |
Discussion
Symantec Enterprise Firewall/VPN Appliance Multiple Remote Vulnerabilities
Symantec Enterprise Firewall/VPN Appliance is affected by multiple remote vulnerabilities. These issues are due to a failure of the application to handle exceptional conditions, a default configuration issue exists as well.
An attacker can leverage a denial of service issue to cause the affected appliance to stop responding, requiring a power off to bring the device back to functionality. A filter bypass issue allows an attacker to bypass the filters on the 'tftpd', 'snmpd', and 'isakmp' services. An attacker can also read and write the community string of the affected device by default, facilitating disclosure and altering of the device's settings.
Symantec Nexland legacy firewall appliances are also affected by these issues.
Symantec Enterprise Firewall/VPN Appliance is affected by multiple remote vulnerabilities. These issues are due to a failure of the application to handle exceptional conditions, a default configuration issue exists as well.
An attacker can leverage a denial of service issue to cause the affected appliance to stop responding, requiring a power off to bring the device back to functionality. A filter bypass issue allows an attacker to bypass the filters on the 'tftpd', 'snmpd', and 'isakmp' services. An attacker can also read and write the community string of the affected device by default, facilitating disclosure and altering of the device's settings.
Symantec Nexland legacy firewall appliances are also affected by these issues.
Exploit / POC
Symantec Enterprise Firewall/VPN Appliance Multiple Remote Vulnerabilities
No exploit is required to leverage any of these issues.
No exploit is required to leverage any of these issues.
Solution / Fix
Symantec Enterprise Firewall/VPN Appliance Multiple Remote Vulnerabilities
Solution:
The vendor has provided an updated firmware dealing with these issues.
Users with the Symantec Enterprise Firewall/VPN Appliances devices are advised to update their firmware to firmware build 1.63. Users of Symantec Gateway Security devices are advised to upgrade to firmware build 622. Please contact the vendor for more information on obtaining fixes.
Users with Nexland legacy firewall appliances may address this issue by updating to firmware build 16U.
Solution:
The vendor has provided an updated firmware dealing with these issues.
Users with the Symantec Enterprise Firewall/VPN Appliances devices are advised to update their firmware to firmware build 1.63. Users of Symantec Gateway Security devices are advised to upgrade to firmware build 622. Please contact the vendor for more information on obtaining fixes.
Users with Nexland legacy firewall appliances may address this issue by updating to firmware build 16U.
References
Symantec Enterprise Firewall/VPN Appliance Multiple Remote Vulnerabilities
References:
References:
- Enterprise Support (Symantec)
- SYM04-013 Symantec Enterprise Firewall/VPN and Gateway Security 300 Series (Symantec)
- Symantec Gateway Security Home Page (Symantec)
- Symantec Homepage (Symantec)
- Multiple Vulnerabilities in Symantec Enterprise Firewall/Gateway Security ("Mike Sues"
)