F5 FirePass 5.4 through 5.5.1 does not properly enforce host access restrictions when a client uses a single integer (dword) representation of an IP address ("dotless IP address"), which allows remote authenticated users to connect to the FirePass administrator console and certain other network resources.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:25
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html - | |
References | () http://secunia.com/advisories/23640 - | |
References | () http://www.mnin.org/advisories/2007_firepass.pdf - | |
References | () http://www.osvdb.org/32734 - | |
References | () http://www.securityfocus.com/bid/21957 - | |
References | () https://tech.f5.com/home/solutions/sol6922.html - |
Information
Published : 2007-01-12 05:04
Updated : 2024-11-21 00:25
NVD link : CVE-2007-0188
Mitre link : CVE-2007-0188
CVE.ORG link : CVE-2007-0188
JSON object : View
Products Affected
f5
- firepass
CWE