Korean
<< Back
VID 210068
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The Web server is vulnerable to a denial of service attack via the web management interface in Packeteer PacketShaper. Packeteer PacketShaper versions 7.3.0g2 and 7.5.0g1 are vulnerable to a denial of service vulnerability in the Web management interface. An authenticated remote attacker with read-only or higher access could exploit this vulnerability by sending a request with empty values of the OP.MEAS.DATAQUERY and MEAS.TYPE parameters to cause the device to reboot.

* Note: This check solely relied on the version number of the Packeteer PacketShaper program installed on the remote Web server to assess this vulnerability, so this might be a false positive.

* References:
http://www.securityfocus.com/archive/1/470835/30/0/threaded
http://secunia.com/advisories/25577

* Platforms Affected:
Packeteer PacketShaper 7.3.0g2
Packeteer PacketShaper 7.5.0g1
Recommendation No upgrade or patch available as of August 2006.

As a workaround, restrict access to trusted IP addresses only.
Related URL CVE-2007-3151 (CVE)
Related URL 24388 (SecurityFocus)
Related URL 34780 (ISS)