Vulnerabilities > CVE-2001-0402

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
darren-reed
freebsd
openbsd
exploit available

Summary

IPFilter 3.4.16 and earlier does not include sufficient session information in its cache, which allows remote attackers to bypass access restrictions by sending fragmented packets to a restricted port after sending unfragmented packets to an unrestricted port.

Exploit-Db

descriptionIPFilter 3.x Fragment Rule Bypass Vulnerability. CVE-2001-0402. Remote exploit for unix platform
idEDB-ID:20730
last seen2016-02-02
modified2001-04-09
published2001-04-09
reporterThomas Lopatic
sourcehttps://www.exploit-db.com/download/20730/
titleIPFilter 3.x Fragment Rule Bypass Vulnerability