Portscan Bypass Vulnerability in Symantec Norton Personal Firewall
CVE-2002-1778

Currently unrated

Key Information:

Vendor
Symantec
Vendor
CVE Published:
31 December 2002

Summary

The Norton Personal Firewall 2002 developed by Symantec is susceptible to a portscan bypass vulnerability that enables remote attackers to circumvent the firewall's portscan protection mechanisms. This is achieved by exploiting the TCP SYN/FIN flags in various combinations: (1) SYN/FIN, (2) SYN/FIN/URG, (3) SYN/FIN/PUSH, or (4) SYN/FIN/URG/PUSH. Attackers may leverage this flaw to probe the network's open ports without triggering alerts designed to protect against such scans, potentially exposing sensitive systems to further attacks.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.