CVE-2000-0220: Medium severity Zonelabs ZoneAlarm vulnerability
ZoneAlarm sends sensitive system and network information in cleartext to the Zone Labs server if a user requests more information about an event.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable or do not use the 'request more information' / 'send additional event details' behavior so ZoneAlarm does not transmit system or network details to the Zone Labs server.
ZoneAlarm request_more_information = disabled - Compensating control
At the network perimeter, block or restrict outbound connections from affected hosts to the Zone Labs server(s) (egress firewall rules/ACLs) to prevent cleartext transmission of sensitive system and network information.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0220?
The severity of CVE-2000-0220 is considered moderate as it exposes sensitive information over an unsecured channel.
How do I fix CVE-2000-0220?
To fix CVE-2000-0220, upgrade to a version of ZoneAlarm that addresses this vulnerability and ensure that sensitive data is transmitted securely.
What information does CVE-2000-0220 expose?
CVE-2000-0220 exposes sensitive system and network information in cleartext.
Which version of ZoneAlarm is affected by CVE-2000-0220?
CVE-2000-0220 specifically affects ZoneAlarm version 2.0.26.
Is it safe to use ZoneAlarm version 2.0.26 after CVE-2000-0220?
Using ZoneAlarm version 2.0.26 is not safe due to CVE-2000-0220 as it may lead to sensitive information being compromised.