CVE-2007-6098 Information

Description

Ingate Firewall before 4.6.0 and SIParator before 4.6.0 do not log truncated (1) ICMP (2) UDP and (3) TCP packets which has unknown impact and remote attack vectors; and do not log (4) serial-console login attempts with nonexistent usernames which might make it easier for attackers with physical access to guess valid login credentials while avoiding detection.

Reference

http://www.ingate.com/relnote-460.php http://www.securityfocus.com/bid/26486

Share on: