7.5
CVSSv2

CVE-2000-0339

Published: 24/04/2000 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

ZoneAlarm 2.1.10 and previous versions does not filter UDP packets with a source port of 67, which allows remote malicious users to bypass the firewall rules.

Vulnerable Product Search on Vulmon Subscribe to Product

zonelabs zonealarm

Exploits

source: wwwsecurityfocuscom/bid/1137/info Certain versions of Zone Labs personal Firewall have a vulnerability which allows malicious users to port scan the firewall without being detected In particular if the port scan originates from source port 67 on the attacking host the ZoneAlarm fails to register the attack nmap -g67 -P0 -p130-1 ...