5
CVSSv2

CVE-2002-0209

Published: 16/05/2002 Updated: 11/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Nortel Alteon ACEdirector WebOS 9.0, with the Server Load Balancing (SLB) and Cookie-Based Persistence features enabled, allows remote malicious users to determine the real IP address of a web server with a half-closed session, which causes ACEdirector to send packets from the server without changing the address to the virtual IP address.

Vulnerable Product Search on Vulmon Subscribe to Product

nortel alteon acedirector 9.0

Exploits

source: wwwsecurityfocuscom/bid/3964/info Alteon ACEdirector is a hardware solution distributed by Nortel Networks ACEdirector runs the Nortel WebOS operating system It is possible to retrieve the real IP addresses of webservers that are managed by an ACEdirector When a client is connected to a webserver via the virtual IP address of ...