Vulnerability Description
Nokia Firewall Appliances running IPSO 3.3 and VPN-1/FireWall-1 4.1 Service Pack 3, IPSO 3.4 and VPN-1/FireWall-1 4.1 Service Pack 4, and IPSO 3.4 or IPSO 3.4.1 and VPN-1/FireWall-1 4.1 Service Pack 5, when SYN Defender is configured in Active Gateway mode, does not properly rewrite the third packet of a TCP three-way handshake to use the NAT IP address, which allows remote attackers to gain sensitive information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Checkpoint | Firewall-1 | 4.1 |
| Checkpoint | Vpn-1 | 4.1 |
| Nokia | Firewall Appliance | ipso_3.3 |
References
- http://www.kb.cert.org/vuls/id/258731US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8293
- http://www.kb.cert.org/vuls/id/258731US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8293
FAQ
What is CVE-2001-1431?
CVE-2001-1431 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Nokia Firewall Appliances running IPSO 3.3 and VPN-1/FireWall-1 4.1 Service Pack 3, IPSO 3.4 and VPN-1/FireWall-1 4.1 Service Pack 4, and IPSO 3.4 or IPSO 3.4.1 and VPN-1/FireWall-1 4.1 Service Pack 5...
How severe is CVE-2001-1431?
CVE-2001-1431 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-1431?
Check the references section above for vendor advisories and patch information. Affected products include: Checkpoint Firewall-1, Checkpoint Vpn-1, Nokia Firewall Appliance.