Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PF in certain OpenBSD versions, when stateful filtering is enabled, does not limit packets for a session to the original interface, which allows remote attackers to bypass intended packet filters via spoofed packets to other interfaces.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenBSD PF状态跟踪欺骗包漏洞
Vulnerability Description
OpenBSD PF是OpenBSD系统下实现的包过滤系统。 OpenBSD PF当状态检测启动时处理包存在问题,远程攻击者可以利用这个漏洞绕过PF的通信过滤。 当状态检测建立后,PF会匹配进出接口包状态的特征,如UDP/TCP的相同端口,源/目的IP)。如果在一个接口上建立了一个IKE通信的状态,那么任何使用伪造IP的IKE包就能从任意接口进入防火墙,而无视接口上的PF规则。
CVSS Information
N/A
Vulnerability Type
N/A