The 3Com TippingPoint IPS do not properly handle certain full-width and half-width Unicode character encodings in an HTTP POST request, which might allow remote attackers to evade detection of HTTP traffic.
oryginał ENCVSS Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P3com 3crtpx505 73
HW3Comwszystkie wersje3com 3crx506 96
HW3Comwszystkie wersje3com Tippingpoint 200
HW3Comwszystkie wersje3com Tippingpoint 200e
HW3Comwszystkie wersje3com Tippingpoint 2400e
HW3Comwszystkie wersje3com Tippingpoint 50
HW3Comwszystkie wersje3com Tippingpoint 5000e
HW3Comwszystkie wersje3com Tippingpoint 600e
HW3Comwszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Referencje
Powiązane podatności
CVE-2001-1291CRITICAL9.8PL ✓ten sam vendor
Brak mechanizmu blokowania prób logowania w serwerze Telnet urządzeń 3Com
CVE-2008-6395HIGH7.8ten sam vendor
The web management interface in 3Com Wireless 8760 Dual Radio 11a/b/g PoE Access Point allows remote attackers...
CVE-2007-5419HIGH10.0ten sam vendor
The 3Com 3CRWER100-75 router with 1.2.10ww software, when enabling an optional virtual server, configures this...
CVE-2007-3711HIGH7.5ten sam vendor
Unspecified vulnerability in TOS 2.1.x, 2.2.x before 2.2.5, and 2.5.x before 2.5.2 on TippingPoint IPS allows ...
CVE-2007-3701HIGH7.5ten sam vendor
TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) characte...