CVE-2003-0106 describes a vulnerability in Symantec Enterprise Firewall (SEF) 7.0 where its HTTP proxy allows users to bypass URL pattern matching for blocked sites. This bypass is achieved by using URL-encoded escapes, Unicode, or UTF-8 in requests. With a CVSS score of 7.5, this vulnerability is considered high severity, allowing for potential information disclosure, modification, and availability impacts with low attack complexity and no authentication required. Despite its age, there is no known active exploitation, public exploit code, or KEV listing, though it has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0CPE matchmatch criteria | cpe:2.3:a:symantec:enterprise_firewall:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.