First published: Thu Jul 05 2001(Updated: )
The default configuration of the config.http.tunnel.allow_ports option on NetCache devices is set to +all, which allows remote attackers to connect to arbitrary ports on remote systems behind the device.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Network Appliance NetCache | =c700 | |
Network Appliance NetCache | =c3100 | |
Network Appliance NetCache | =c6100 | |
Network Appliance NetCache | =c1100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1087 has a critical severity rating due to the potential for remote attackers to exploit the vulnerability.
To fix CVE-2001-1087, configure the config.http.tunnel.allow_ports option to restrict access to only necessary ports.
CVE-2001-1087 affects the default configuration of the Network Appliance NetCache models c1100, c3100, c6100, and c700.
Attackers can connect to arbitrary ports on remote systems behind the NetCache devices due to the default configuration.
Yes, a workaround involves changing the default configuration to limit the ports allowed through the NetCache device.