MEDIUM · 5.0

CVE-2002-1937

Symantec Firewall/VPN Appliance 100 through 200R hardcodes the administrator's MAC address inside the firewall's configuration, which allows remote attackers to spoof the administrator's MAC address a...

Vulnerability Description

Symantec Firewall/VPN Appliance 100 through 200R hardcodes the administrator's MAC address inside the firewall's configuration, which allows remote attackers to spoof the administrator's MAC address and perform an ARP poisoning man-in-the-middle attack to obtain the administrator's password.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
SymantecFirewall Vpn Appliance 100All versions
SymantecFirewall Vpn Appliance 200All versions
SymantecFirewall Vpn Appliance 200RAll versions

References

FAQ

What is CVE-2002-1937?

CVE-2002-1937 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Symantec Firewall/VPN Appliance 100 through 200R hardcodes the administrator's MAC address inside the firewall's configuration, which allows remote attackers to spoof the administrator's MAC address a...

How severe is CVE-2002-1937?

CVE-2002-1937 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-1937?

Check the references section above for vendor advisories and patch information. Affected products include: Symantec Firewall Vpn Appliance 100, Symantec Firewall Vpn Appliance 200, Symantec Firewall Vpn Appliance 200R.