CVE-2007-3701

TippingPoint IPS - Signature Evasion via Hex-Encoded Unicode Slash Character

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-3701. PoCs published by Security-Assessment.com.

AI-analyzed exploit summary The exploit demonstrates a detection-bypass vulnerability in TippingPoint IPS by using Unicode characters to obfuscate malicious URIs. It provides examples of encoded paths that can bypass filtering mechanisms.

Description

TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) character, which might allow remote attackers to send certain network traffic and avoid detection, as demonstrated by a cmd.exe attack.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Security-Assessment.com · textremotewindows
https://www.exploit-db.com/exploits/30287

The exploit demonstrates a detection-bypass vulnerability in TippingPoint IPS by using Unicode characters to obfuscate malicious URIs. It provides examples of encoded paths that can bypass filtering mechanisms.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: TippingPoint IPS
No auth needed
Prerequisites: Access to a vulnerable TippingPoint IPS appliance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24855
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26013
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018361
Patch, Vendor Advisory x_refsource_confirm
http://www.3com.com/securityalert/alerts/3COM-07-003.html
Mailing List mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2007-July/064550.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2490
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/473311/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/35336
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/35970

Scores

EPSS 0.0968
EPSS Percentile 93.0%

Details

CWE
CWE-20
Status published
Products (23)
3com/tippingpoint_ips_tos 2.1
3com/tippingpoint_ips_tos 2.1.4.6324
3com/tippingpoint_ips_tos 2.2
3com/tippingpoint_ips_tos 2.2.1
3com/tippingpoint_ips_tos 2.2.1.6506
3com/tippingpoint_ips_tos 2.2.2
3com/tippingpoint_ips_tos 2.2.3
3com/tippingpoint_ips_tos 2.2.4
3com/tippingpoint_ips_tos 2.5
3com/tippingpoint_ips_tos 2.5.1
... and 13 more
Published Jul 11, 2007
Tracked Since Feb 18, 2026