Vulnerability Details CVE-2001-1087
The default configuration of the config.http.tunnel.allow_ports option on NetCache devices is set to +all, which allows remote attackers to connect to arbitrary ports on remote systems behind the device.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 71.2%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2001-1087
-
cpe:2.3:h:network_appliance:netcache:c1100
-
cpe:2.3:h:network_appliance:netcache:c3100
-
cpe:2.3:h:network_appliance:netcache:c6100
-
cpe:2.3:h:network_appliance:netcache:c700