The 3Com TippingPoint IPS do not properly handle certain full-width and half-width Unicode character encodings in an HTTP POST request, which might allow remote attackers to evade detection of HTTP traffic.
CVSS Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P3com 3crtpx505 73
HW3Comall versions3com 3crx506 96
HW3Comall versions3com Tippingpoint 200
HW3Comall versions3com Tippingpoint 200e
HW3Comall versions3com Tippingpoint 2400e
HW3Comall versions3com Tippingpoint 50
HW3Comall versions3com Tippingpoint 5000e
HW3Comall versions3com Tippingpoint 600e
HW3Comall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
References
Related vulnerabilities
CVE-2001-1291CRITICAL9.8PL ✓same vendor
Brak mechanizmu blokowania prób logowania w serwerze Telnet urządzeń 3Com
CVE-2008-6395HIGH7.8same vendor
The web management interface in 3Com Wireless 8760 Dual Radio 11a/b/g PoE Access Point allows remote attackers...
CVE-2007-5419HIGH10.0same vendor
The 3Com 3CRWER100-75 router with 1.2.10ww software, when enabling an optional virtual server, configures this...
CVE-2007-3711HIGH7.5same vendor
Unspecified vulnerability in TOS 2.1.x, 2.2.x before 2.2.5, and 2.5.x before 2.5.2 on TippingPoint IPS allows ...
CVE-2007-3701HIGH7.5same vendor
TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) characte...