Lucene search

K
ciscoCiscoCISCO-SA-20070214-CVE-2007-0959
HistoryFeb 14, 2007 - 9:57 p.m.

Cisco PIX and ASA TCP Traffic Inspection Denial of Service Vulnerability

2007-02-1421:57:58
tools.cisco.com
10

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.063

Percentile

93.6%

Cisco PIX 500 Series Security Appliances and Cisco ASA 5500 Series Adaptive Security Appliances (ASA) contain a vulnerability that could allow an unauthenticated, remote attacker to crash an affected device, causing a denial of service (DoS) condition.

This vulnerability exists due to insufficient handling of malformed TCP packet streams. An unauthenticated, remote attacker could exploit this vulnerability by sending a crafted series of packets to the affected device. This could allow an attacker to crash the device, resulting in a DoS condition.

Cisco confirmed this vulnerability in a security advisory and released updated software.

For a system to be vulnerable, it must be configured for inspection of a TCP-based protocol. This is done using the inspect command and specifying any application that uses the TCP protocol. This would include FTP and HTTP, which are both TCP based and are configured for inspection by default. Affected devices are vulnerable in their default configurations.

Because the affected devices are typically deployed along the perimeter of a corporate site, they may be vulnerable to attack if they have ports open for traffic from untrusted users. This would include allowing traffic in to access a web or FTP server. Fortunately, there is a workaround that fixes this problem. All administrators are advised to configure this workaround
at their earliest convenience.

Affected configurations

Vulners
Node
ciscopix_asa_idsMatchany
OR
ciscopix_asa_idsMatchany
VendorProductVersionCPE
ciscopix_asa_idsanycpe:2.3:a:cisco:pix_asa_ids:any:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.063

Percentile

93.6%

Related for CISCO-SA-20070214-CVE-2007-0959