Nortel Networks Information for VU#539363

State-based firewalls fail to effectively manage session table resource exhaustion

Status

Not Affected

Vendor Statement

The following Nortel Networks products use state-based firewall technology:

The Alteon Switched Firewall incorporates FireWall-1 technology licensed from Check Point Software Technologies, Inc. Please refer to the Vendor Statement posted by Check Point Software Technologies, Inc.

There are no issues with the Contivity Platform, this includes the:

    Contivity 600/1500/1600/2000/2500/2600/4500/4600
    Contivity 1010/1050/1100
    Contivity 1700/2700
    Contivity software releases 3.5 and beyond including the CVC Client
The Shasta 5000 Broadband Services Node is not affected.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Vendor References

None

Addendum

This statement was submitted to the CERT/CC on Tuesday, November 5, 2002.

If you have feedback, comments, or additional information about this vulnerability, please send us email.