ID

VAR-200505-0595


CVE

CVE-2005-0311


TITLE

Ingate Firewall Persistent PPTP Tunnel Vulnerability

Trust: 0.9

sources: BID: 12383 // CNNVD: CNNVD-200505-554

DESCRIPTION

Ingate Firewall 4.1.3 and earlier does not terminate the PPTP session for an active user when the administrator disables that user from a resource, which could allow remote authenticated users to retain unauthorized access to resources. Ingate Firewall does not remove PPTP tunnels created by a user that has been disabled by the firewall administrator. Even if the user has been disabled, any PPTP tunnels they have created will persist

Trust: 1.26

sources: NVD: CVE-2005-0311 // BID: 12383 // VULHUB: VHN-11520

AFFECTED PRODUCTS

vendor:ingatemodel:firewallscope:eqversion:4.1.3

Trust: 1.9

vendor:ingatemodel:firewallscope:eqversion:3.3.1

Trust: 1.9

vendor:ingatemodel:firewallscope:eqversion:3.2.1

Trust: 1.9

vendor:ingatemodel:firewallscope:eqversion:3.2

Trust: 1.9

sources: BID: 12383 // CNNVD: CNNVD-200505-554 // NVD: CVE-2005-0311

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2005-0311
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200505-554
value: MEDIUM

Trust: 0.6

VULHUB: VHN-11520
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2005-0311
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-11520
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-11520 // CNNVD: CNNVD-200505-554 // NVD: CVE-2005-0311

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2005-0311

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-200505-554

TYPE

Design Error

Trust: 0.9

sources: BID: 12383 // CNNVD: CNNVD-200505-554

EXTERNAL IDS

db:BIDid:12383

Trust: 2.0

db:SECUNIAid:14060

Trust: 1.7

db:SECTRACKid:1013022

Trust: 1.7

db:NVDid:CVE-2005-0311

Trust: 1.7

db:CNNVDid:CNNVD-200505-554

Trust: 0.7

db:BUGTRAQid:20050127 INGATE FIREWALL: REMOVED PPTP TUNNELS NOT DEACTIVATED

Trust: 0.6

db:XFid:19123

Trust: 0.6

db:VULHUBid:VHN-11520

Trust: 0.1

sources: VULHUB: VHN-11520 // BID: 12383 // CNNVD: CNNVD-200505-554 // NVD: CVE-2005-0311

REFERENCES

url:http://www.securityfocus.com/bid/12383

Trust: 1.7

url:http://www.ingate.com/relnote-422.php

Trust: 1.7

url:http://securitytracker.com/id?1013022

Trust: 1.7

url:http://secunia.com/advisories/14060

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/19123

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=110684375429946&w=2

Trust: 1.0

url:http://xforce.iss.net/xforce/xfdb/19123

Trust: 0.6

url:http://marc.theaimsgroup.com/?l=bugtraq&m=110684375429946&w=2

Trust: 0.6

url:http://www.ingate.com/

Trust: 0.3

url:/archive/1/388520

Trust: 0.3

url:http://marc.info/?l=bugtraq&m=110684375429946&w=2

Trust: 0.1

sources: VULHUB: VHN-11520 // BID: 12383 // CNNVD: CNNVD-200505-554 // NVD: CVE-2005-0311

CREDITS

Discovery is credited to Neil Watson at Voicegenie.

Trust: 0.9

sources: BID: 12383 // CNNVD: CNNVD-200505-554

SOURCES

db:VULHUBid:VHN-11520
db:BIDid:12383
db:CNNVDid:CNNVD-200505-554
db:NVDid:CVE-2005-0311

LAST UPDATE DATE

2024-08-14T15:20:11.019000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-11520date:2017-07-11T00:00:00
db:BIDid:12383date:2005-01-27T00:00:00
db:CNNVDid:CNNVD-200505-554date:2005-10-20T00:00:00
db:NVDid:CVE-2005-0311date:2017-07-11T01:32:13.140

SOURCES RELEASE DATE

db:VULHUBid:VHN-11520date:2005-05-02T00:00:00
db:BIDid:12383date:2005-01-27T00:00:00
db:CNNVDid:CNNVD-200505-554date:2005-05-02T00:00:00
db:NVDid:CVE-2005-0311date:2005-05-02T04:00:00