Portscan Bypass Vulnerability in Symantec Norton Personal Firewall
CVE-2002-1778
Currently unrated
Summary
The Norton Personal Firewall 2002 developed by Symantec is susceptible to a portscan bypass vulnerability that enables remote attackers to circumvent the firewall's portscan protection mechanisms. This is achieved by exploiting the TCP SYN/FIN flags in various combinations: (1) SYN/FIN, (2) SYN/FIN/URG, (3) SYN/FIN/PUSH, or (4) SYN/FIN/URG/PUSH. Attackers may leverage this flaw to probe the network's open ports without triggering alerts designed to protect against such scans, potentially exposing sensitive systems to further attacks.
References
Timeline
Vulnerability Reserved
Vulnerability published