ID

VAR-200107-0020


CVE

CVE-2001-1104


TITLE

SonicWALL SOHO Security hole

Trust: 0.6

sources: CNNVD: CNNVD-200107-176

DESCRIPTION

SonicWALL SOHO uses easily predictable TCP sequence numbers, which allows remote attackers to spoof or hijack sessions. By predicting a sequence number, several attacks could be performed; an attacker could disrupt or hijack existing connections, or spoof future connections

Trust: 1.26

sources: NVD: CVE-2001-1104 // BID: 3098 // VULHUB: VHN-3909

AFFECTED PRODUCTS

vendor:sonicwallmodel:sohoscope:eqversion:5.1.5.0

Trust: 1.9

vendor:sonicwallmodel:sohoscope:eqversion:5.0.0

Trust: 1.9

vendor:sonicwallmodel:sohoscope:eqversion:4.0.0

Trust: 1.9

sources: BID: 3098 // CNNVD: CNNVD-200107-176 // NVD: CVE-2001-1104

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2001-1104
value: HIGH

Trust: 1.0

CNNVD: CNNVD-200107-176
value: LOW

Trust: 0.6

VULHUB: VHN-3909
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2001-1104
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-3909
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-3909 // CNNVD: CNNVD-200107-176 // NVD: CVE-2001-1104

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2001-1104

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200107-176

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-200107-176

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-3909

EXTERNAL IDS

db:BIDid:3098

Trust: 2.0

db:NVDid:CVE-2001-1104

Trust: 2.0

db:CNNVDid:CNNVD-200107-176

Trust: 0.7

db:EXPLOIT-DBid:19522

Trust: 0.1

db:VULHUBid:VHN-3909

Trust: 0.1

sources: VULHUB: VHN-3909 // BID: 3098 // CNNVD: CNNVD-200107-176 // NVD: CVE-2001-1104

REFERENCES

url:http://www.securityfocus.com/bid/3098

Trust: 1.7

url:http://www.securityfocus.com/archive/1/199632

Trust: 1.7

url:http://www.sonicwall.com

Trust: 0.3

sources: VULHUB: VHN-3909 // BID: 3098 // CNNVD: CNNVD-200107-176 // NVD: CVE-2001-1104

CREDITS

Reported to Bugtraq by Dan Ferris <danf@percept.com> on July 25, 2001.

Trust: 0.9

sources: BID: 3098 // CNNVD: CNNVD-200107-176

SOURCES

db:VULHUBid:VHN-3909
db:BIDid:3098
db:CNNVDid:CNNVD-200107-176
db:NVDid:CVE-2001-1104

LAST UPDATE DATE

2024-08-14T12:44:31.922000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-3909date:2008-09-05T00:00:00
db:BIDid:3098date:2009-07-11T06:56:00
db:CNNVDid:CNNVD-200107-176date:2022-06-30T00:00:00
db:NVDid:CVE-2001-1104date:2022-06-28T18:37:19.573

SOURCES RELEASE DATE

db:VULHUBid:VHN-3909date:2001-07-25T00:00:00
db:BIDid:3098date:2001-07-25T00:00:00
db:CNNVDid:CNNVD-200107-176date:2001-07-25T00:00:00
db:NVDid:CVE-2001-1104date:2001-07-25T04:00:00