Vulnerability Description
The 3Com TippingPoint IPS do not properly handle certain full-width and half-width Unicode character encodings in an HTTP POST request, which might allow remote attackers to evade detection of HTTP traffic.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 3Com | 3Crtpx505-73 | All versions |
| 3Com | 3Crx506-96 | All versions |
| 3Com | Tippingpoint 200 | All versions |
| 3Com | Tippingpoint 200E | All versions |
| 3Com | Tippingpoint 2400E | All versions |
| 3Com | Tippingpoint 50 | All versions |
| 3Com | Tippingpoint 5000E | All versions |
| 3Com | Tippingpoint 600E | All versions |
References
- http://osvdb.org/35968
- http://secunia.com/advisories/25302PatchVendor Advisory
- http://securityreason.com/securityalert/2712
- http://www.3com.com/securityalert/alerts/3COM-07-001.html
- http://www.gamasec.net/english/gs07-01.html
- http://www.kb.cert.org/vuls/id/739224US Government Resource
- http://www.securityfocus.com/archive/1/468633/100/0/threaded
- http://www.vupen.com/english/advisories/2007/1817
- http://osvdb.org/35968
- http://secunia.com/advisories/25302PatchVendor Advisory
- http://securityreason.com/securityalert/2712
- http://www.3com.com/securityalert/alerts/3COM-07-001.html
- http://www.gamasec.net/english/gs07-01.html
- http://www.kb.cert.org/vuls/id/739224US Government Resource
- http://www.securityfocus.com/archive/1/468633/100/0/threaded
FAQ
What is CVE-2007-2734?
CVE-2007-2734 is a vulnerability with a CVSS score of 7.5 (HIGH). The 3Com TippingPoint IPS do not properly handle certain full-width and half-width Unicode character encodings in an HTTP POST request, which might allow remote attackers to evade detection of HTTP tr...
How severe is CVE-2007-2734?
CVE-2007-2734 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-2734?
Check the references section above for vendor advisories and patch information. Affected products include: 3Com 3Crtpx505-73, 3Com 3Crx506-96, 3Com Tippingpoint 200, 3Com Tippingpoint 200E, 3Com Tippingpoint 2400E.