SecureScoutLogo.jpg
Computer Associates eTrust Intrusion Detection System DoS Vulnerability



Go to Vulnerabilities List


General Info


TC: 11007
Description: The transmission of several thousands of discovery packets, each having a unique MAC address, will make the Computer Associates e Trust Intrusion Detection System (formerly known as SessionWall-3) unstable. While being run on Windows NT, the user interface will crash but will continue to capture sessions. CPU usage will be exhausted in Windows 9x. Restarting the application will be required in order to regain normal functionality.
TC Impact: Denial of Service



Specific Operations and Actions:


Vulnerability Publication: June 7, 2000
Advisory Copyright: Codex
Summary: Someone can disturb your eTrust IDS service.
Risk: Medium
CVSS 2.0 metrics: Access Vector: Network
Access Complexity: Low
Authentication: None
Confidentiality Impact: None
Integrity Impact: None
Availability Impact: Partial
CVSS 2.0 Base Score: 5.0
Vulnerability Impact: Denial of Service
Host Impact: Your IDS is not working properly.
Nature of Remediation: Update the software.
Step required to fix the reported vulnerability:

***** Solution type: Upgrade Software *****

Upgrade to the latest version of the software.
See references for more details.



Glossary and References :


References:
* MISC: Product info
http://www.cai.com/solutions/enterprise/etrust/intrusion_detection/
* BID:
http://www.securityfocus.com/bid/1342

CVE Link: GENERIC-MAP-NOMATCH
CVE Compatible

Glossary: Denial of Service
IDS


© 2003-2010 NexantiS Corporation (www.securescout.com)
SecureScout is a trademark of NexantiS
All Rights Reserved
All products names referenced herein are trademarks of their respective companies

SecureScout products are certified:
CVE Compatible
SANS TOP 20 Compatible
CVSS Compatible (Common Vulnerability Scoring System)