Lucene search

K
ciscoCiscoCISCO-SA-20110928-ZBFW
HistorySep 28, 2011 - 4:00 p.m.

Cisco IOS Software IPS and Zone Based Firewall Vulnerabilities

2011-09-2816:00:00
tools.cisco.com
25

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.002

Percentile

52.0%

Cisco IOS Software contains two vulnerabilities related to Cisco IOS
Intrusion Prevention System (IPS) and Cisco IOS Zone-Based Firewall features.
These vulnerabilities are:

Memory leak in Cisco IOS Software

Cisco IOS Software Denial of Service when processing specially
crafted HTTP packets

Cisco has released software updates that address these vulnerabilities.

Workarounds that mitigate these vulnerabilities are not
available.

This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20110928-zbfw[“[[Publication_URL]]”].

Note: The September 28, 2011, Cisco IOS Software
Security Advisory bundled publication includes ten Cisco Security Advisories.
Nine of the advisories address vulnerabilities in Cisco IOS Software, and one
advisory addresses a vulnerability in Cisco Unified Communications Manager.
Each advisory lists the Cisco IOS Software releases that correct the
vulnerability or vulnerabilities detailed in the advisory as well as the Cisco
IOS Software releases that correct all vulnerabilities in the September 2011
Bundled Publication.

Individual publication links are in “Cisco Event Response:
Semiannual Cisco IOS Software Security Advisory Bundled Publication” at the
following link:

http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_sep11.html[“http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_sep11.html”]

[“http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_sep11.html”]

Affected configurations

Vulners
Node
ciscoiosMatch15.0m
OR
ciscoiosMatch15.0xa
OR
ciscoiosMatch15.1t
OR
ciscoiosMatch15.1xb
OR
ciscoiosMatch15.1m
OR
ciscoiosMatch15.1gc
OR
ciscoiosMatch15.0\(1\)m1
OR
ciscoiosMatch15.0\(1\)m5
OR
ciscoiosMatch15.0\(1\)m4
OR
ciscoiosMatch15.0\(1\)m3
OR
ciscoiosMatch15.0\(1\)m2
OR
ciscoiosMatch15.0\(1\)m6
OR
ciscoiosMatch15.0\(1\)m
OR
ciscoiosMatch15.0\(1\)xa2
OR
ciscoiosMatch15.0\(1\)xa4
OR
ciscoiosMatch15.0\(1\)xa1
OR
ciscoiosMatch15.0\(1\)xa3
OR
ciscoiosMatch15.0\(1\)xa
OR
ciscoiosMatch15.0\(1\)xa5
OR
ciscoiosMatch15.1\(2\)t
OR
ciscoiosMatch15.1\(1\)t1
OR
ciscoiosMatch15.1\(2\)t0a
OR
ciscoiosMatch15.1\(1\)t3
OR
ciscoiosMatch15.1\(2\)t3
OR
ciscoiosMatch15.1\(1\)t2
OR
ciscoiosMatch15.1\(3\)t
OR
ciscoiosMatch15.1\(2\)t2a
OR
ciscoiosMatch15.1\(3\)t1
OR
ciscoiosMatch15.1\(1\)t
OR
ciscoiosMatch15.1\(2\)t2
OR
ciscoiosMatch15.1\(2\)t1
OR
ciscoiosMatch15.1\(1\)xb
OR
ciscoiosMatch15.1\(1\)xb3
OR
ciscoiosMatch15.1\(1\)xb1
OR
ciscoiosMatch15.1\(1\)xb2
OR
ciscoiosMatch15.1\(4\)xb4
OR
ciscoiosMatch15.1\(4\)m
OR
ciscoiosMatch15.1\(4\)m0a
OR
ciscoiosMatch15.1\(4\)m0b
OR
ciscoiosMatch15.1\(2\)gc
OR
ciscoiosMatch15.1\(2\)gc1

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.002

Percentile

52.0%

Related for CISCO-SA-20110928-ZBFW