First published: Thu Nov 22 2007(Updated: )
Ingate Firewall before 4.6.0 and SIParator before 4.6.0 do not log truncated (1) ICMP, (2) UDP, and (3) TCP packets, which has unknown impact and remote attack vectors; and do not log (4) serial-console login attempts with nonexistent usernames, which might make it easier for attackers with physical access to guess valid login credentials while avoiding detection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ingate Ingate Siparator | <=4.5.2 | |
Ingate Ingate Firewall | <=4.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.