CVE-2007-6098: High severity Ingate Ingate Firewall vulnerability
Ingate Firewall before 4.6.0 and SIParator before 4.6.0 do not log truncated (1) ICMP, (2) UDP, and (3) TCP packets, which has unknown impact and remote attack vectors; and do not log (4) serial-console login attempts with nonexistent usernames, which might make it easier for attackers with physical access to guess valid login credentials while avoiding detection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6098?
CVE-2007-6098 is considered to have unknown impact and lacks a formally assigned CVSS severity score.
How do I fix CVE-2007-6098?
To fix CVE-2007-6098, upgrade Ingate Firewall and SIParator to version 4.6.0 or higher.
What types of packets are not logged in CVE-2007-6098?
CVE-2007-6098 does not log truncated ICMP, UDP, and TCP packets.
What login attempts are not recorded according to CVE-2007-6098?
CVE-2007-6098 does not log serial-console login attempts with nonexistent usernames.
What is the potential risk of CVE-2007-6098?
The lack of logging in CVE-2007-6098 may allow attackers to exploit vulnerabilities without detection.