CVE-2021-33600

MEDIUM

F-Secure Internet Gatekeeper 5.10-5.50.47 - Unauthenticated Denial of Service via Malformed HTTP Packet

Title source: llm
STIX 2.1

Description

A denial-of-service (DoS) vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. The vulnerability occurs because of an attacker can trigger assertion via malformed HTTP packet to web interface. An unauthenticated attacker could exploit this vulnerability by sending a large username parameter. A successful exploitation could lead to a denial-of-service of the product.

Scores

CVSS v3 5.4
EPSS 0.0059
EPSS Percentile 43.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-617
Status published
Products (1)
f-secure/internet_gatekeeper 5.10 - 5.50.47
Published Sep 28, 2021
Tracked Since Feb 18, 2026