CVE-2006-2341
The HTTP proxy in Symantec Gateway Security 5000 Series 2.0.1 and 3.0, and Enterprise Firewall 8.0, when NAT is being used, allows remote attackers to determine internal IP addresses by using malformed HTTP requests, as demonstrated using a get request without a space separating the URI.
Published:May 12, 2006
Last Modified:Apr 16, 2026
EPS:May 12, 2006
EPSS Score:0.101
CVSS Score:5
Affected Products
Vendor
Product
Action
Vendor
Symantec
Product
Enterprise Firewall
Symantec
Enterprise Firewall
Vendor
Symantec
Product
Gateway Security
Symantec
Gateway Security
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
