vendor:
FreeIPS
by:
7.5
CVSS
HIGH
Denial of Service
CWE
Product Name: FreeIPS
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Denial of Service Vulnerability in FreeIPS
FreeIPS is susceptible to a denial of service vulnerability. It scans TCP connections for particular strings defined by regular expressions. If a packet matches the regular expression, FreeIPS assumes malicious intent and attempts to close the TCP connection. However, the packet sent to the server is incorrectly generated and contains invalid sequence and acknowledgment numbers, which are ignored. An attacker can exploit this vulnerability to deny service to any TCP application protected by FreeIPS, thereby denying network service to legitimate users. The attacker would need to know or guess a string pattern that matches a regular expression in FreeIPS.
Mitigation:
Update FreeIPS to a version that addresses this vulnerability. If an update is not available, consider using an alternative IPS solution.