Vulnerability Name:

CVE-2005-0817 (CCN-44530)

Assigned:2004-06-15
Published:2004-06-15
Updated:2017-07-11
Summary:Unknown vulnerability in the DNSd proxy, as used in Symantec Gateway Security 5400 2.x and 5300 1.x, Enterprise Firewall 7.0.x and 8.x, and VelociRaptor 1100/1200/1300 1.5, allows remote attackers to poison the DNS cache and redirect users to malicious sites.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: BUGTRAQ
Type: UNKNOWN
20040615 Symantec Enterprise Firewall DNSD cache poisoning Vulnerability

Source: CCN
Type: BugTraq Mailing List, Tue Jun 15 2004 - 12:45:37 CDT
Symantec Enterprise Firewall DNSD cache poisoning Vulnerability

Source: CCN
Type: BugTraq Mailing List, Wed Jun 16 2004 - 12:56:31 CDT
Re: Symantec Enterprise Firewall DNSD cache poisoning Vulnerability

Source: MITRE
Type: CNA
CVE-2005-0817

Source: CCN
Type: SA14595
Symantec Products Unspecified DNS Cache Poisoning Vulnerability

Source: SECUNIA
Type: UNKNOWN
14595

Source: CCN
Type: Symantec Security Advisory SYM05-005
Symantec security gateway DNS redirection

Source: CONFIRM
Type: Vendor Advisory
http://securityresponse.symantec.com/avcenter/security/Content/2005.03.15.html

Source: CCN
Type: SECTRACK ID: 1013451
Symantec VelociRaptor DNSd Proxy Bug Lets Remote Users Poison the DNS Cache

Source: SECTRACK
Type: UNKNOWN
1013451

Source: MISC
Type: UNKNOWN
http://www.isc.sans.org/diary.php?date=2005-03-04

Source: CCN
Type: OSVDB ID: 14802
Symantec Multiple Products Unspecified DNS Cache Poisoning

Source: XF
Type: UNKNOWN
sef-dns-spoofing(16423)

Source: XF
Type: UNKNOWN
symantec-dnsdproxy-redirect(44530)

Source: XF
Type: UNKNOWN
symantec-dnsdproxy-redirect(44530)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:symantec:enterprise_firewall:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:enterprise_firewall:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:velociraptor:model_1300:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/h:symantec:gateway_security_5300:1.0:*:*:*:*:*:*:*
  • OR cpe:/h:symantec:gateway_security_5400:2.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:symantec:enterprise_firewall:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:enterprise_firewall:8.0:*:*:*:*:*:*:*
  • OR cpe:/h:symantec:gateway_security:5300_1.0:*:*:*:*:*:*:*
  • OR cpe:/h:symantec:gateway_security:5400_2.0:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:velociraptor:1300:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    symantec enterprise firewall 7.0
    symantec enterprise firewall 8.0
    symantec velociraptor model_1300
    symantec gateway security 5300 1.0
    symantec gateway security 5400 2.0
    symantec enterprise firewall 7.0
    symantec enterprise firewall 8.0
    symantec gateway security 5300_1.0
    symantec gateway security 5400_2.0
    symantec velociraptor 1300