SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Your Ad Here
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  Device (Intrusion Detection)  >  TippingPoint Intrusion Prevention System Vendors:  3Com
TippingPoint Intrusion Prevention System Lets Remote Users Bypass the Detection Mechanism
SecurityTracker Alert ID:  1016562
SecurityTracker URL:  http://securitytracker.com/id?1016562
CVE Reference:  CVE-2006-3678   (Links to External Site)
Updated:  Jun 13 2008
Original Entry Date:  Jul 24 2006
Impact:  Denial of service via network
Fix Available:  Yes   Vendor Confirmed:  Yes  
Version(s): 2.2.3.6514 and prior versions
Description:  A vulnerability was reported in the TippingPoint Intrusion Prevention System. A remote user can shutdown the detection mechanism.

A remote user can send a specially crafted packet to cause the target device to fallback to layer 2 mode, where all traffic is forwarded without inspection.

The vendor was notified on June 2, 2006.

Andres Riancho of CYBSEC reported this vulnerability.

Impact:  A remote user can shutdown the detection mechanism.
Solution:  The vendor issued a fix (on July 21, 2006).
Vendor URL:  www.3com.com/ (Links to External Site)
Cause:  Exception handling error
Reported By:  "Andres Riancho" <ariancho@cybsec.com>
Message History:   None.


 Source Message Contents

Date:  Mon, 24 Jul 2006 07:41:24 -0400
From:  "Andres Riancho" <ariancho@cybsec.com>
Subject:  [CYBSEC] TippingPoint detection bypass

 
CYBSEC S.A.
www.cybsec.com

Pre-Advisory Name: TippingPoint detection bypass
==============

Vulnerability Class: Design flaw
==============

Release Date: 07/24/2006
==========

Affected Platforms:
=============
* All TippingPoint appliances with TOS <= 2.2.3.6514

Local / Remote: Remote
===========

Severity: High
======

Author: Andres Riancho
=====

Vendor Status:
===========
* Confirmed, update released.

Reference to Vulnerability Disclosure Policy:
================================
http://www.cybsec.com/vulnerability_policy.pdf

Vulnerability Description:
==================
A malformed packet can force the appliance to fallback to layer 2 mode. In this mode the appliance fo
rwards all traffic without inspection. Technical Details: ============= Technical details will be released 30 days after publication of this pre-advisory. This was agreed up
on with TippingPoint to allow their customers to upgrade affected software prior to technical knowledge been publicly available. Impact: ===== Exploiting this vulnerability, an attacker would be able to bypass all filters and detection. Solutions: ======= TippingPoint has released a new version of the TippingPoint OS to address this vulnerability. Custome
rs should apply the new firmware immediately. Vendor Response: ============= * 06/02/2005: Initial Vendor Contact. * 06/20/2006: Vendor Confirmed Vulnerability. * 07/21/2006: Vendor Releases Update. * 07/24/2006: Pre-Advisory Public Disclosure. Contact Information: ============== For more information regarding the vulnerability feel free to contact the author at ariancho {at} cyb
sec.com. For more information regarding CYBSEC: www.cybsec.com (c) 2006 - CYBSEC S.A. Security Systems -- ---------------------------- Andres Riancho CYBSEC S.A. Security Systems E-mail: ariancho@cybsec.com PGP key: http://pgp.mit.edu:11371/pks/lookup?op=index&search=ariancho Tel/Fax: [54-11] 4371-4444 Web: http://www.cybsec.com -----------------------------


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2007, SecurityGlobal.net LLC