Lucene search

K
ciscoCiscoCISCO-SA-20070214-CVE-2007-0962
HistoryFeb 14, 2007 - 9:51 p.m.

Cisco Firewall Services Module, PIX, and ASA Malformed HTTP Requests Denial of Service Vulnerability

2007-02-1421:51:53
tools.cisco.com
10

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.04

Percentile

92.1%

Cisco Firewall Services Module, Cisco PIX Security Appliance, and Cisco Adaptive Security Appliance (ASA) contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.

The vulnerability exists due to an error within the handling of malformed HTTP requests. An attacker could exploit this vulnerability via a malformed HTTP request to cause the device to reload, resulting in a DoS condition.

Cisco confirmed this vulnerability in a security advisory and released updated software.

Enhanced inspection of HTTP requests is not enabled by default on any of the affected products. Normal inspection, which is enabled by using the inspect http command without specifying an HTTP map, will not make a system vulnerable.

Affected configurations

Vulners
Node
ciscofirewall_services_moduleMatchany
OR
ciscopix_asa_idsMatchany
OR
ciscofirewall_services_moduleMatchany
OR
ciscopix_asa_idsMatchany
VendorProductVersionCPE
ciscofirewall_services_moduleanycpe:2.3:h:cisco:firewall_services_module:any:*:*:*:*:*:*:*
ciscopix_asa_idsanycpe:2.3:a:cisco:pix_asa_ids:any:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.04

Percentile

92.1%

Related for CISCO-SA-20070214-CVE-2007-0962