Cisco Application Velocity System Open TCP Proxy Vulnerability

BID:17937

CVE-2006-2322 |

Info

Cisco Application Velocity System Open TCP Proxy Vulnerability

Bugtraq ID: 17937
Class: Access Validation Error
CVE:
Remote: Yes
Local: No
Published: May 10 2006 12:00AM
Updated: May 15 2006 05:59PM
Credit: The vendor disclosed this issue.
Vulnerable: Cisco Application Velocity System 3120 5.0
Cisco Application Velocity System 3110 5.0
Cisco Application Velocity System 3110 4.0
Not Vulnerable: Cisco Application Velocity System 3120 5.0.1
Cisco Application Velocity System 3110 5.0.1

Discussion

Cisco Application Velocity System Open TCP Proxy Vulnerability

Cisco Application Velocity System (AVS) is susceptible to a remote open TCP proxy vulnerability. This software fails to allow only valid TCP ports to be used by remote users.

Remote attackers may use the affected software as an open TCP proxy. Attackers have exploited this to send unsolicited commercial email (UCE).

Versions of AVS prior to 5.0.1 are vulnerable to this issue.

Exploit / POC

Cisco Application Velocity System Open TCP Proxy Vulnerability

Attackers use readily available network utilities to exploit this issue.

Solution / Fix

Cisco Application Velocity System Open TCP Proxy Vulnerability

Solution:
Cisco has released an advisory along with fixes to address this issue. Please see the referenced advisory for further information.

Note that the instructions given in the workaround section must still be performed after fixes have been applied.

References

Cisco Application Velocity System Open TCP Proxy Vulnerability

References:
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report