CVE-2001-1104: High severity SonicWall Soho Firmware vulnerability
Published Jul 25, 2001
·Updated
SonicWALL SOHO uses easily predictable TCP sequence numbers, which allows remote attackers to spoof or hijack sessions.
Affected Software
4 affected components
SonicWall Soho Firmware=4.0.0
SonicWall SOHO
SonicWall Soho Firmware=5.0.0
SonicWall Soho Firmware=5.1.5.0
Event History
Jul 25, 2001
CVE Published
04:00 AM
Data Sourced
04:00 AM
DescriptionWeaknessAffected Software
Mar 15, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1104?
CVE-2001-1104 is classified as a medium severity vulnerability that allows attackers to spoof or hijack sessions.
2
How do I fix CVE-2001-1104?
To fix CVE-2001-1104, upgrade the SonicWALL SOHO firmware to a version later than 5.1.5.0 that addresses the predictable TCP sequence number issue.
3
Which SonicWALL SOHO firmware versions are affected by CVE-2001-1104?
CVE-2001-1104 affects SonicWALL SOHO firmware versions 4.0.0 and 5.0.0.
4
Can CVE-2001-1104 be exploited remotely?
Yes, CVE-2001-1104 can be exploited remotely by attackers to spoof or hijack active sessions.
5
What type of vulnerability is CVE-2001-1104?
CVE-2001-1104 is a TCP sequence number prediction vulnerability.