Symantec has announced that several of its firewalls and gateways are vulnerable to denial of service attacks, and has released firmware to fix them. Affected are Symantec Firewall/VPN Appliance 100, 200 and 200R and the Symantec Gateway Security 320, 360 and 360R.
Symantec noted on its Web site that the vulnerabilities "are remotely exploitable and can allow an attacker to perform a denial of service attack against the firewall appliance, identify active services in the WAN interface, and exploit one of these services to collect and alter the firewall's configuration." The Symantec Firewall/VPN Appliances, models 100, 200 and 200R are vulnerable to all three attacks, while the Symantec Gateway Security models 320, 360 and 360R are not vulnerable to the Denial of Service attack, but are vulnerable to the other two.
|