Vulnerability Name:

CVE-2007-3537 (CCN-35173)

Assigned:2007-06-29
Published:2007-06-29
Updated:2017-07-29
Summary:IBM OS/400 (aka i5/OS) V4R2M0 through V5R3M0 on iSeries machines sends responses to TCP SYN-FIN packets, which allows remote attackers to obtain system information and possibly bypass firewall rules.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N)
5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): None
Availibility (A): None
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2007-3537

Source: OSVDB
Type: UNKNOWN
37792

Source: CCN
Type: SA25885
IBM OS/400 TCP Packet Processing Security Bypass Issue

Source: SECUNIA
Type: Vendor Advisory
25885

Source: AIXAPAR
Type: UNKNOWN
MA28921

Source: CCN
Type: IBM APAR MA28921
LIC-COMM-TCPIP PACKET WITH SYN AND FIN FLAG NOT DISCARDED

Source: CCN
Type: OSVDB ID: 37792
IBM OS/400 on iSeries TCP SYN-FIN Packet Handling Security Bypass

Source: BID
Type: UNKNOWN
24706

Source: CCN
Type: BID-24706
IBM OS/400 TCP Packet Security Bypass Weakness

Source: XF
Type: UNKNOWN
os400-tcpsyn-security-bypass(35173)

Source: XF
Type: UNKNOWN
os400-tcpsyn-security-bypass(35173)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:ibm:os_400:r520:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:os_400:v4r2m0:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:os_400:v4r3:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:os_400:v4r4:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:os_400:v4r5:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:os_400:v5r1:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:os_400:v5r2m0:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:os_400:v5r3m0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:ibm:os_400:v5r3m0:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:os_400:v4r2m0:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:os_400:v5r2m0:*:*:*:*:*:*:*
  • AND
  • cpe:/o:ibm:i5os:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    ibm os 400 r520
    ibm os 400 v4r2m0
    ibm os 400 v4r3
    ibm os 400 v4r4
    ibm os 400 v4r5
    ibm os 400 v5r1
    ibm os 400 v5r2m0
    ibm os 400 v5r3m0
    ibm os 400 v5r3m0
    ibm os 400 v4r2m0
    ibm os 400 v5r2m0
    ibm i5os *