This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Symantec First view 2002-12-31
Product Firewall Vpn Appliance 200r Last view 2005-05-02
Version Type Hardware
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:h:symantec:firewall_vpn_appliance_200r:*:*:*:*:*:*:*:* 6

Related : CVE

  Date Alert Description
6.4 2005-05-02 CVE-2005-0618

The SMTP binding function in Symantec Firewall/VPN Appliance 200/200R firmware after 1.5Z and before 1.68, Gateway Security 360/360R and 460/460R firmware before vuild 858, and Nexland Pro800turbo, when configured for load balancing between two WANs, might send SMTP traffic to a trusted network through an untrusted network.

5 2004-12-31 CVE-2004-1474

Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 uses a default read/write SNMP community string, which allows remote attackers to alter the firewall's configuration file.

5 2004-12-31 CVE-2004-1473

Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 allow remote attackers to bypass filtering and determine whether the device is running services such as tftpd, snmpd, or isakmp via a UDP port scan with a source port of UDP 53.

5 2004-12-31 CVE-2004-1472

Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 allow remote attackers to cause a denial of service (device freeze) via a fast UDP port scan on the WAN interface.

7.5 2004-03-15 CVE-2004-0190

Symantec FireWall/VPN Appliance model 200 records a cleartext password for the password administration page, which may be cached on the administrator's local system or in a proxy, which allows attackers to steal the password and gain privileges.

5 2002-12-31 CVE-2002-1937

Symantec Firewall/VPN Appliance 100 through 200R hardcodes the administrator's MAC address inside the firewall's configuration, which allows remote attackers to spoof the administrator's MAC address and perform an ARP poisoning man-in-the-middle attack to obtain the administrator's password.

Open Source Vulnerability Database (OSVDB)

id Description
59900 Symantec Firewall / VPN Appliance Hardcoded Administrator MAC Address Weakness
14271 Symantec Multiple Firewall SMTP Binding Configuration Bypass
10206 Symantec Firewall/Gateway Default SNMP String Allows Device Configuration Dis...
10205 Symantec Firewall/Gateway UDP Port 53 Filter Bypass
10204 Symantec Enterprise Firewall/VPN Appliance UDP Port Scan DoS
4117 Symantec Firewall / VPN Appliance Exposure of Password

Nessus® Vulnerability Scanner

id Description
2003-05-06 Name: Firewall rulesets can be bypassed.
File: kerio_PF_udpbypass.nasl - Type: ACT_ATTACK
2002-11-25 Name: The community names of the remote SNMP server can be guessed.
File: snmp_default_communities.nasl - Type: ACT_GATHER_INFO