CVE-2007-3701 describes a vulnerability in TippingPoint IPS devices prior to the 20070710 update, where improper handling of hex-encoded alternate Unicode slash characters allows attackers to bypass detection of malicious network traffic, such as cmd.exe attacks. With a CVSS score of 7.5, this vulnerability is considered highly severe due to its network-based attack vector, low attack complexity, and potential for partial compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, an ExploitDB entry exists, and there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
50CPE matchmatch criteria | cpe:2.3:a:tippingpoint:tipping_point:50:*:*:*:*:*:*:* | ||
200CPE matchmatch criteria | cpe:2.3:a:tippingpoint:tipping_point:200:*:*:*:*:*:*:* | ||
200eCPE matchmatch criteria | cpe:2.3:a:tippingpoint:tipping_point:200e:*:*:*:*:*:*:* | ||
400CPE matchmatch criteria | cpe:2.3:a:tippingpoint:tipping_point:400:*:*:*:*:*:*:* | ||
600eCPE matchmatch criteria | cpe:2.3:a:tippingpoint:tipping_point:600e:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.