HIGH · 7.5

CVE-2007-2734

The 3Com TippingPoint IPS do not properly handle certain full-width and half-width Unicode character encodings in an HTTP POST request, which might allow remote attackers to evade detection of HTTP tr...

Vulnerability Description

The 3Com TippingPoint IPS do not properly handle certain full-width and half-width Unicode character encodings in an HTTP POST request, which might allow remote attackers to evade detection of HTTP traffic.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
3Com3Crtpx505-73All versions
3Com3Crx506-96All versions
3ComTippingpoint 200All versions
3ComTippingpoint 200EAll versions
3ComTippingpoint 2400EAll versions
3ComTippingpoint 50All versions
3ComTippingpoint 5000EAll versions
3ComTippingpoint 600EAll versions

References

FAQ

What is CVE-2007-2734?

CVE-2007-2734 is a vulnerability with a CVSS score of 7.5 (HIGH). The 3Com TippingPoint IPS do not properly handle certain full-width and half-width Unicode character encodings in an HTTP POST request, which might allow remote attackers to evade detection of HTTP tr...

How severe is CVE-2007-2734?

CVE-2007-2734 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-2734?

Check the references section above for vendor advisories and patch information. Affected products include: 3Com 3Crtpx505-73, 3Com 3Crx506-96, 3Com Tippingpoint 200, 3Com Tippingpoint 200E, 3Com Tippingpoint 2400E.