CVE-2021-33600
MEDIUMF-Secure Internet Gatekeeper 5.10-5.50.47 - Unauthenticated Denial of Service via Malformed HTTP Packet
Title source: llmDescription
A denial-of-service (DoS) vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. The vulnerability occurs because of an attacker can trigger assertion via malformed HTTP packet to web interface. An unauthenticated attacker could exploit this vulnerability by sending a large username parameter. A successful exploitation could lead to a denial-of-service of the product.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://www.f-secure.com/en/business/programs/vulnerability-reward-program/hall-of-fame
Vendor Advisory x_refsource_misc
https://www.f-secure.com/en/business/support-and-downloads/security-advisories/cve-2021-33600
Scores
CVSS v3
5.4
EPSS
0.0059
EPSS Percentile
43.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-617
Status
published
Products (1)
f-secure/internet_gatekeeper
5.10 - 5.50.47
Published
Sep 28, 2021
Tracked Since
Feb 18, 2026