Vulnerability Name: | CVE-2007-2897 (CCN-34418) | ||||||||
Assigned: | 2007-05-21 | ||||||||
Published: | 2007-05-21 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | Microsoft Internet Information Services (IIS) 6.0 allows remote attackers to cause a denial of service (server instability or device hang), and possibly obtain sensitive information (device communication traffic); and might allow attackers with physical access to execute arbitrary code after connecting a data stream to a device COM port; via requests for a URI containing a '/' immediately before and after the name of a DOS device, as demonstrated by the /AUX/.aspx URI, which bypasses a blacklist for DOS device requests. | ||||||||
CVSS v3 Severity: | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 6.4 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:U/RC:UR)
6.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:POC/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: FULLDISC Type: UNKNOWN 20070523 Re: Question Regarding IIS 6.0 / Is this a DoS??? Source: MITRE Type: CNA CVE-2007-2897 Source: FULLDISC Type: UNKNOWN 20070522 Question Regarding IIS 6.0 / Is this a DoS??? Source: CCN Type: Microsoft Internet Information Services Web site Internet Information Services Source: CCN Type: OSVDB ID: 41057 Microsoft IIS w/ .NET MS-DOS Device Request Blacklist Bypass Source: XF Type: UNKNOWN iis-auxaspx-dos(34418) Source: XF Type: UNKNOWN iis-auxaspx-dos(34418) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |