CVE-2002-0990

3 documents3 sources
Severity
5.0MEDIUM
EPSS
1.1%
top 22.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 28
Latest updateApr 30

Description

The web proxy component in Symantec Enterprise Firewall (SEF) 6.5.2 through 7.0, Raptor Firewall 6.5 and 6.5.3, VelociRaptor, and Symantec Gateway Security allow remote attackers to cause a denial of service (connection resource exhaustion) via multiple connection requests to domains whose DNS server is unresponsive or does not exist, which generates a long timeout.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

NVDsymantec/raptor_firewall6.5, 6.5.3+1
NVDsymantec/velociraptor6 versions+5
NVDsymantec/gateway_security5110, 5200, 5300+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gpqc-h3w5-77f4: The web proxy component in Symantec Enterprise Firewall (SEF) 62022-04-30
CVEList
CVE-2002-0990: The web proxy component in Symantec Enterprise Firewall (SEF) 62004-09-01