Title : Cisco IPS Full/Half Width Unicode Characters Handling Detection Evasion Vulnerability VUPEN ID : VUPEN/ADV-2007-1803 CVE ID : CVE-2007-2688
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-05-14
Technical Description
A vulnerability has been identified in Cisco Intrusion Prevention System (IPS) and Cisco IOS with Firewall/IPS Feature Set, which could be exploited by remote attackers to bypass security checks. This issue is caused by an error when processing requests containing full-width or half-width unicode characters, which could be exploited by remote attackers to evade IPS or firewall detection and covertly scan and attack systems protected by an affected device.