CVE-2002-0309
Estado: ModificadaMedia (5)—
SMTP proxy in Symantec Enterprise Firewall (SEF) 6.5.x includes the firewall's physical interface name and address in an SMTP protocol exchange when NAT translation is made to an address other than the firewall, which could allow remote attackers to determine certain firewall configuration information.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.66%
- Percentil entre todas las CVEs puntuadas: 76
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://marc.info/?l=bugtraq&m=101424307617060&w=2
- http://marc.info/?l=bugtraq&m=101430810813853&w=2
- http://securityresponse.symantec.com/avcenter/security/Content/2002.02.20.html
- http://www.iss.net/security_center/static/8251.php
- http://www.securityfocus.com/bid/4141
- http://marc.info/?l=bugtraq&m=101424307617060&w=2
- http://marc.info/?l=bugtraq&m=101430810813853&w=2
- http://securityresponse.symantec.com/avcenter/security/Content/2002.02.20.html
- http://www.iss.net/security_center/static/8251.php
- http://www.securityfocus.com/bid/4141
JSON original (NVD)
Mostrar
{
"id": "CVE-2002-0309",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2002-05-31T04:00:00.000",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=101424307617060&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=101430810813853&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://securityresponse.symantec.com/avcenter/security/Content/2002.02.20.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.iss.net/security_center/static/8251.php",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/4141",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=101424307617060&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=bugtraq&m=101430810813853&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityresponse.symantec.com/avcenter/security/Content/2002.02.20.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.iss.net/security_center/static/8251.php",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/4141",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SMTP proxy in Symantec Enterprise Firewall (SEF) 6.5.x includes the firewall's physical interface name and address in an SMTP protocol exchange when NAT translation is made to an address other than the firewall, which could allow remote attackers to determine certain firewall configuration information."
},
{
"lang": "es",
"value": "El proxy SMTP en Symantec Enterprise Firewall 6.5.x incluye el nombre y la dirección del interfaz físico del cortafuegos en un intercambio de mensajes SMTP cuando la traduzzión NAT (network address translation) se hace a una dirección distinta de la del cortafuegos, lo que podría permitir a atacantes remotos determinar cierta información de configuarción del cortafuegos."
}
],
"lastModified": "2026-06-16T21:57:11.397",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:symantec:enterprise_firewall:6.5.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "60CD39A5-0059-4E17-8F4F-58F23589A408"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}