20001003 Cisco PIX Firewall allow external users to discover internal IPsmailing list
http://marc.info/?l=bugtraq&m=97059440000367&w=2 CVE-2000-1027
Cisco PIX Firewall 5.2 - PASV Mode FTP Internal Address Disclosure
Record summary
CVE-2000-1027 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server with PASV requests, which includes the real IP address in the response when passive mode is established.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCisco PIX Firewall 5.2 - PASV Mode FTP Internal Address DisclosureExploitDB exploitby Fabio PietrosantiNot analyzed1 file
References
51623vdb entry
http://www.osvdb.org/1623 1877vdb entry
http://www.securityfocus.com/bid/1877 cisco-pix-reveal-address(5646)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/5646 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-1027