Vulnerability Description
Multiple IBM ISS Proventia Series products, including the A, G, and M series, do not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Iss | Proventia A Series Xpu | <= 22.10 |
| Iss | Proventia G Series Xpu | <= 22.11 |
| Iss | Proventia M Series Xpu | <= 1.9 |
References
- http://www.gamasec.net/english/gs07-01.html
- http://www.kb.cert.org/vuls/id/739224US Government Resource
- http://www.securityfocus.com/archive/1/468633/100/0/threaded
- http://www.securitytracker.com/id?1018068
- http://www.gamasec.net/english/gs07-01.html
- http://www.kb.cert.org/vuls/id/739224US Government Resource
- http://www.securityfocus.com/archive/1/468633/100/0/threaded
- http://www.securitytracker.com/id?1018068
FAQ
What is CVE-2007-2690?
CVE-2007-2690 is a vulnerability with a CVSS score of 7.8 (HIGH). Multiple IBM ISS Proventia Series products, including the A, G, and M series, do not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers t...
How severe is CVE-2007-2690?
CVE-2007-2690 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-2690?
Check the references section above for vendor advisories and patch information. Affected products include: Iss Proventia A Series Xpu, Iss Proventia G Series Xpu, Iss Proventia M Series Xpu.