« Volver al listado

CVE-2001-1431

Estado: ModificadaMedia (5)—

Nokia Firewall Appliances running IPSO 3.3 and VPN-1/FireWall-1 4.1 Service Pack 3, IPSO 3.4 and VPN-1/FireWall-1 4.1 Service Pack 4, and IPSO 3.4 or IPSO 3.4.1 and VPN-1/FireWall-1 4.1 Service Pack 5, when SYN Defender is configured in Active Gateway mode, does not properly rewrite the third packet of a TCP three-way handshake to use the NAT IP address, which allows remote attackers to gain sensitive information.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2001-1431",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2001-10-08T04:00:00.000",
  "references": [
    {
      "url": "http://www.kb.cert.org/vuls/id/258731",
      "tags": [
        "US Government Resource"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/8293",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/258731",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/8293",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Nokia Firewall Appliances running IPSO 3.3 and VPN-1/FireWall-1 4.1 Service Pack 3, IPSO 3.4 and VPN-1/FireWall-1 4.1 Service Pack 4, and IPSO 3.4 or IPSO 3.4.1 and VPN-1/FireWall-1 4.1 Service Pack 5, when SYN Defender is configured in Active Gateway mode, does not properly rewrite the third packet of a TCP three-way handshake to use the NAT IP address, which allows remote attackers to gain sensitive information."
    }
  ],
  "lastModified": "2026-06-16T21:56:15.687",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:checkpoint:firewall-1:4.1:sp3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "997ABD78-6DF8-440C-B90A-E5CD7C6ACA75"
            },
            {
              "criteria": "cpe:2.3:a:checkpoint:firewall-1:4.1:sp4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60536AAF-76BC-4773-98FA-5F01E2D231FB"
            },
            {
              "criteria": "cpe:2.3:a:checkpoint:firewall-1:4.1:sp5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E4206C4-05A7-46D1-90C7-6BA7744C7AD9"
            },
            {
              "criteria": "cpe:2.3:a:checkpoint:vpn-1:4.1:sp3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9754CCE-CEC5-4359-9C62-133885817DEF"
            },
            {
              "criteria": "cpe:2.3:a:checkpoint:vpn-1:4.1:sp4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C65FC343-69C9-4B70-8149-42297B47C813"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:nokia:firewall_appliance:ipso_3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8B11266A-90C4-47B9-B6DD-77F1B4701708"
            },
            {
              "criteria": "cpe:2.3:h:nokia:firewall_appliance:ipso_3.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E24EF8C6-E623-4B37-96D6-D514ECE365B4"
            },
            {
              "criteria": "cpe:2.3:h:nokia:firewall_appliance:ipso_3.41:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F781F5B-B875-4119-937B-97286E746C91"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}