HTTP Proxy Disclosure in Symantec Gateway Security and Enterprise Firewall
CVE-2006-2341

Currently unrated

Key Information:

Vendor
Symantec
Vendor
CVE Published:
12 May 2006

Summary

The HTTP proxy in certain versions of Symantec Gateway Security 5000 Series and Enterprise Firewall, when using Network Address Translation (NAT), is vulnerable to attacks that can reveal internal IP addresses. This vulnerability arises when attackers send malformed HTTP requests, which exploit the proxy's inability to properly handle specific request formats. This flaw can potentially allow unauthorized individuals to gain insight into the network's internal structure, posing a serious risk to the integrity and confidentiality of the affected environment. Users of these products should take immediate steps to mitigate this issue.

References

EPSS Score

8% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.