Junglewise Threat Intelligence

CVE-1999-0290: Qbik WinGate denial of service in telnet proxy

CVE-1999-0290 · Severity: medium · CVSS 5 · Published 1998-02-21

Executive brief

WinGate is a proxy server used to manage internet connectivity and security for local networks. A vulnerability in its telnet proxy component allows remote attackers to crash the service or make it unavailable by flooding it with connection requests. This can disrupt network operations and prevent legitimate users from accessing remote systems through the proxy.

Technical details

The WinGate telnet proxy service is vulnerable to a resource exhaustion or denial of service attack. By initiating a high volume of connections directed at the localhost interface through the proxy, a remote, unauthenticated attacker can overwhelm the service. This results in the proxy becoming unresponsive to legitimate traffic. The vulnerability is reachable over the network without prior authentication.

Affected products

  • Qbik WinGate unknown

Timeline

  • 1998-02-21: disclosed: Vulnerability first published in NVD.

References