ID

VAR-200108-0113


CVE

CVE-2001-0589


TITLE

NetScreen-10 and Netscreen-100 NetScreen ScreenOS Vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200108-094

DESCRIPTION

NetScreen ScreenOS prior to 2.5r6 on the NetScreen-10 and Netscreen-100 can allow a local attacker to bypass the DMZ 'denial' policy via specific traffic patterns. NetScreen is a line of internet security appliances inetgrating firewall, VPN and traffic management features. Versions of ScreenOS, the inbuild OS of two models in the NetScreen line (NetScreen-10 & -100) contain a flaw which may permit some packets, of a type which has been denied, to enter the DMZ. As a result of this vulnerability, potentially malicious packets of a type which has been prohibited in the device's policy may, to a limited extent, reach the DMZ network. Further details of this vulnerability were not made available. Versions prior to NetScreen ScreenOS 2.5r6 on NetScreen-10 and Netscreen-100 are vulnerable

Trust: 1.26

sources: NVD: CVE-2001-0589 // BID: 2523 // VULHUB: VHN-3403

AFFECTED PRODUCTS

vendor:junipermodel:netscreen screenosscope:eqversion:1.66

Trust: 1.6

vendor:junipermodel:netscreen screenosscope:eqversion:2.1

Trust: 1.6

vendor:junipermodel:netscreen screenosscope:eqversion:1.64

Trust: 1.6

vendor:junipermodel:netscreen screenosscope:eqversion:2.5

Trust: 1.6

vendor:netscreenmodel:screenosscope:eqversion:2.5

Trust: 0.3

vendor:netscreenmodel:screenosscope:eqversion:2.1

Trust: 0.3

vendor:netscreenmodel:screenosscope:eqversion:1.66

Trust: 0.3

vendor:netscreenmodel:screenosscope:eqversion:1.64

Trust: 0.3

vendor:netscreenmodel:screenos r6scope:neversion:2.5

Trust: 0.3

vendor:netscreenmodel:screenos r8scope:neversion:2.0.1

Trust: 0.3

vendor:netscreenmodel:screenos r2scope:neversion:1.66

Trust: 0.3

sources: BID: 2523 // CNNVD: CNNVD-200108-094 // NVD: CVE-2001-0589

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2001-0589
value: LOW

Trust: 1.0

CNNVD: CNNVD-200108-094
value: LOW

Trust: 0.6

VULHUB: VHN-3403
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2001-0589
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-3403
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-3403 // CNNVD: CNNVD-200108-094 // NVD: CVE-2001-0589

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2001-0589

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-200108-094

TYPE

Unknown

Trust: 0.9

sources: BID: 2523 // CNNVD: CNNVD-200108-094

EXTERNAL IDS

db:BIDid:2523

Trust: 2.0

db:NVDid:CVE-2001-0589

Trust: 1.7

db:OSVDBid:1780

Trust: 1.7

db:CNNVDid:CNNVD-200108-094

Trust: 0.7

db:XFid:6317

Trust: 0.6

db:BUGTRAQid:20010326 NETSCREEN: DMZ NETWORK RECEIVES SOME "DENIED" TRAFFIC

Trust: 0.6

db:VULHUBid:VHN-3403

Trust: 0.1

sources: VULHUB: VHN-3403 // BID: 2523 // CNNVD: CNNVD-200108-094 // NVD: CVE-2001-0589

REFERENCES

url:http://www.securityfocus.com/bid/2523

Trust: 1.7

url:http://archives.neohapsis.com/archives/bugtraq/2001-03/0375.html

Trust: 1.7

url:http://www.osvdb.org/1780

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/6317

Trust: 1.1

url:http://xforce.iss.net/static/6317.php

Trust: 0.6

url:http://www.netscreen.com/index.html

Trust: 0.3

url:http://www.netscreen.com/support/updates.html

Trust: 0.3

sources: VULHUB: VHN-3403 // BID: 2523 // CNNVD: CNNVD-200108-094 // NVD: CVE-2001-0589

CREDITS

Reported to bugtraq in a vendor advisory dated March 23, 2001

Trust: 0.3

sources: BID: 2523

SOURCES

db:VULHUBid:VHN-3403
db:BIDid:2523
db:CNNVDid:CNNVD-200108-094
db:NVDid:CVE-2001-0589

LAST UPDATE DATE

2024-08-14T15:36:15.286000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-3403date:2017-10-10T00:00:00
db:BIDid:2523date:2001-03-26T00:00:00
db:CNNVDid:CNNVD-200108-094date:2006-08-23T00:00:00
db:NVDid:CVE-2001-0589date:2017-10-10T01:29:47.890

SOURCES RELEASE DATE

db:VULHUBid:VHN-3403date:2001-08-22T00:00:00
db:BIDid:2523date:2001-03-26T00:00:00
db:CNNVDid:CNNVD-200108-094date:2001-08-22T00:00:00
db:NVDid:CVE-2001-0589date:2001-08-22T04:00:00