Lucene search

K
cveMitreCVE-2007-0962
HistoryFeb 16, 2007 - 12:28 a.m.

CVE-2007-0962

2007-02-1600:28:00
mitre
web.nvd.nist.gov
35
cve-2007-0962
cisco
pix
asa
security appliances
denial of service
http inspection

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

AI Score

6.6

Confidence

High

EPSS

0.04

Percentile

92.1%

Cisco PIX 500 and ASA 5500 Series Security Appliances 7.0 before 7.0(4.14) and 7.1 before 7.1(2.1), and the FWSM 2.x before 2.3(4.12) and 3.x before 3.1(3.24), when “inspect http” is enabled, allows remote attackers to cause a denial of service (device reboot) via malformed HTTP traffic.

Affected configurations

Nvd
Node
ciscofirewall_services_moduleMatch2.3
OR
ciscofirewall_services_moduleMatch3.1
Node
ciscoasa_5500Match7.0
OR
ciscoasa_5500Match7.1
OR
ciscopix_firewall_softwareMatch7.0
OR
ciscopix_firewall_softwareMatch7.1
VendorProductVersionCPE
ciscofirewall_services_module2.3cpe:2.3:h:cisco:firewall_services_module:2.3:*:*:*:*:*:*:*
ciscofirewall_services_module3.1cpe:2.3:h:cisco:firewall_services_module:3.1:*:*:*:*:*:*:*
ciscoasa_55007.0cpe:2.3:h:cisco:asa_5500:7.0:*:*:*:*:*:*:*
ciscoasa_55007.1cpe:2.3:h:cisco:asa_5500:7.1:*:*:*:*:*:*:*
ciscopix_firewall_software7.0cpe:2.3:o:cisco:pix_firewall_software:7.0:*:*:*:*:*:*:*
ciscopix_firewall_software7.1cpe:2.3:o:cisco:pix_firewall_software:7.1:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

AI Score

6.6

Confidence

High

EPSS

0.04

Percentile

92.1%