CVE-2007-1338

Apple AirPort Extreme - Unauthenticated IPv6 Firewall Bypass via Default Configuration

Title source: llm
STIX 2.1

Description

The default configuration of the AirPort utility in Apple AirPort Extreme creates an IPv6 tunnel but does not enable the "Block incoming IPv6 connections" setting, which might allow remote attackers to bypass intended access restrictions by establishing IPv6 sessions that would have been rejected over IPv4.

References (8)

Core 8
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/24830
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1308
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2007/Apr/msg00000.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/33526
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1017889
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/34843
Vendor Advisory x_refsource_confirm
http://docs.info.apple.com/article.html?artnum=305366

Scores

EPSS 0.0266
EPSS Percentile 84.1%

Details

Status published
Products (1)
apple/airport_extreme 7.1
Published Mar 08, 2007
Tracked Since Feb 18, 2026