« Volver al listado

CVE-2007-2734

Estado: ModificadaAlta (7.5)—

The 3Com TippingPoint IPS do not properly handle certain full-width and half-width Unicode character encodings in an HTTP POST request, which might allow remote attackers to evade detection of HTTP traffic.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (8)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-2734",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-05-16T22:30:00.000",
  "references": [
    {
      "url": "http://osvdb.org/35968",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/25302",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/2712",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.3com.com/securityalert/alerts/3COM-07-001.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.gamasec.net/english/gs07-01.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/739224",
      "tags": [
        "US Government Resource"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/468633/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1817",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/35968",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/25302",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/2712",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.3com.com/securityalert/alerts/3COM-07-001.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.gamasec.net/english/gs07-01.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/739224",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/468633/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1817",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The 3Com TippingPoint IPS do not properly handle certain full-width and half-width Unicode character encodings in an HTTP POST request, which might allow remote attackers to evade detection of HTTP traffic."
    },
    {
      "lang": "es",
      "value": "3Com TippingPoint IPS no maneja adecuadamente ciertas codificaciones de caracteres Unicode de ancho total (full-width) o mitad de ancho (half-width) en una petición HTTP POST, lo cual podría permitir a atacantes remotos evadir la detección de tráfico HTTP."
    }
  ],
  "lastModified": "2026-06-16T22:40:12.733",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:3com:3crtpx505-73:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "95D2832C-ABB1-471C-9BBF-FD02DF937CB8"
            },
            {
              "criteria": "cpe:2.3:h:3com:3crx506-96:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C638E694-5A18-4D06-8810-633819C47231"
            },
            {
              "criteria": "cpe:2.3:h:3com:tippingpoint_200:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A351AE89-754D-4170-BC4E-CD2C8262824B"
            },
            {
              "criteria": "cpe:2.3:h:3com:tippingpoint_200e:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D28E50D-36E0-485E-AA78-7D7520FBFC2B"
            },
            {
              "criteria": "cpe:2.3:h:3com:tippingpoint_2400e:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60660614-196A-4F80-B21E-2FE41ACAA69D"
            },
            {
              "criteria": "cpe:2.3:h:3com:tippingpoint_50:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF5ED78C-D90E-4921-893D-D5877BA2E170"
            },
            {
              "criteria": "cpe:2.3:h:3com:tippingpoint_5000e:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7CBF1D4-5446-4900-90E1-722DE3A19D20"
            },
            {
              "criteria": "cpe:2.3:h:3com:tippingpoint_600e:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A8D2B29-E70D-4B2F-AB23-46AB3263FD6B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}