CVE-2007-2690

UnknownEPSS 1.98%

Last modified

CVE-2007-2690 is a vulnerability of currently unknown severity. Multiple IBM ISS Proventia Series products, including the A, G, and M series, do not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.. EPSS estimates a 1.98% chance of exploitation in the next 30 days.

Description

Multiple IBM ISS Proventia Series products, including the A, G, and M series, do not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.

Metrics

EPSS Probability
1.98%

78.0th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
IssProventia A Series Xpu<= 22.10
IssProventia A Series Xpu20.11
IssProventia A Series Xpu22.1
IssProventia A Series Xpu22.2
IssProventia A Series Xpu22.3
IssProventia A Series Xpu22.4
IssProventia A Series Xpu22.5
IssProventia A Series Xpu22.6
IssProventia G Series Xpu<= 22.11
IssProventia G Series Xpu22.1
IssProventia G Series Xpu22.2
IssProventia G Series Xpu22.3
IssProventia G Series Xpu22.4
IssProventia G Series Xpu22.5
IssProventia G Series Xpu22.6
IssProventia G Series Xpu22.7
IssProventia G Series Xpu22.8
IssProventia G Series Xpu22.9
IssProventia G Series Xpu22.10
IssProventia M Series Xpu<= 1.9
IssProventia M Series Xpu1.1
IssProventia M Series Xpu1.2
IssProventia M Series Xpu1.3
IssProventia M Series Xpu1.4
IssProventia M Series Xpu1.5
IssProventia M Series Xpu1.6
IssProventia M Series Xpu1.7
IssProventia M Series Xpu1.8

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2007-2690?
Multiple IBM ISS Proventia Series products, including the A, G, and M series, do not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.
How severe is CVE-2007-2690?
Severity scoring for CVE-2007-2690 is pending analysis. The EPSS model estimates a 1.98% probability of exploitation in the next 30 days.
How do I fix CVE-2007-2690?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2007-2690?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST