First published: Sat Feb 12 2000(Updated: )
Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server by forcing it to send malicious packets that Firewall-1 misinterprets as a valid 227 response to a client's PASV attempt.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Check Point FireWall-1 | =3.0 | |
Check Point FireWall-1 | =4.0 | |
Cisco PIX Firewall | =4.1\(6\) | |
Cisco PIX Firewall | =4.1\(6b\) | |
Cisco PIX Firewall | =4.2\(1\) | |
Cisco PIX Firewall | =4.2\(2\) | |
Cisco PIX Firewall | =4.3 | |
Cisco PIX Firewall | =4.4\(4\) | |
Cisco PIX Firewall | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0150 has a high severity rating due to the potential for unauthorized access to FTP services.
The recommended fix for CVE-2000-0150 is to apply the latest security patches provided by Check Point and Cisco for their respective firewall software.
CVE-2000-0150 affects Check Point FireWall-1 version 3.0 and 4.0, as well as specific versions of Cisco PIX Firewall 4.1(6), 4.1(6b), 4.2(1), 4.2(2), 4.3, and 4.4(4), and 5.0.
Yes, CVE-2000-0150 can be exploited remotely by attackers to bypass FTP port access restrictions.
CVE-2000-0150 involves the misinterpretation of malicious packets by Check Point FireWall-1, allowing unauthorized FTP access.