VID |
210068 |
Severity |
30 |
Port |
80, ... |
Protocol |
TCP |
Class |
CGI |
Detailed Description |
The Web server is vulnerable to a denial of service attack via the web management interface in Packeteer PacketShaper. Packeteer PacketShaper versions 7.3.0g2 and 7.5.0g1 are vulnerable to a denial of service vulnerability in the Web management interface. An authenticated remote attacker with read-only or higher access could exploit this vulnerability by sending a request with empty values of the OP.MEAS.DATAQUERY and MEAS.TYPE parameters to cause the device to reboot.
* Note: This check solely relied on the version number of the Packeteer PacketShaper program installed on the remote Web server to assess this vulnerability, so this might be a false positive.
* References: http://www.securityfocus.com/archive/1/470835/30/0/threaded http://secunia.com/advisories/25577
* Platforms Affected: Packeteer PacketShaper 7.3.0g2 Packeteer PacketShaper 7.5.0g1 |
Recommendation |
No upgrade or patch available as of August 2006.
As a workaround, restrict access to trusted IP addresses only. |
Related URL |
CVE-2007-3151 (CVE) |
Related URL |
24388 (SecurityFocus) |
Related URL |
34780 (ISS) |
|