5
CVSSv2

CVE-2004-1754

Published: 15/06/2004 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The DNS proxy (DNSd) for multiple Symantec Gateway Security products allows remote malicious users to poison the DNS cache via a malicious DNS server query response that contains authoritative or additional records.

Vulnerable Product Search on Vulmon Subscribe to Product

symantec enterprise firewall 8.0

symantec enterprise firewall 7.0.4

symantec gateway security 5200_1.0

symantec gateway security 5310_1.0

symantec gateway security 5400_2.0.1

symantec gateway security 5110_1.0

symantec gateway security 5300_1.0

symantec gateway security 5400_2.0

Exploits

source: wwwsecurityfocuscom/bid/10557/info It is reported that dnsd is prone to a cache poisoning vulnerability Dnsd does not ensure that the data returned from a remote DNS server contains related information about the requested records An attacker could exploit this vulnerability to deny service to legitimate users by redirecting tr ...