Vulnerability Description
Ingate Firewall before 4.6.0 and SIParator before 4.6.0 do not log truncated (1) ICMP, (2) UDP, and (3) TCP packets, which has unknown impact and remote attack vectors; and do not log (4) serial-console login attempts with nonexistent usernames, which might make it easier for attackers with physical access to guess valid login credentials while avoiding detection.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ingate | Ingate Firewall | <= 4.5.2 |
| Ingate | Ingate Siparator | <= 4.5.2 |
References
- http://www.ingate.com/relnote-460.php
- http://www.securityfocus.com/bid/26486
- http://www.ingate.com/relnote-460.php
- http://www.securityfocus.com/bid/26486
FAQ
What is CVE-2007-6098?
CVE-2007-6098 is a vulnerability with a CVSS score of 7.5 (HIGH). Ingate Firewall before 4.6.0 and SIParator before 4.6.0 do not log truncated (1) ICMP, (2) UDP, and (3) TCP packets, which has unknown impact and remote attack vectors; and do not log (4) serial-conso...
How severe is CVE-2007-6098?
CVE-2007-6098 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-6098?
Check the references section above for vendor advisories and patch information. Affected products include: Ingate Ingate Firewall, Ingate Ingate Siparator.