CVE-2007-0959
published 2007-02-16CVE-2007-0959: Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to inspect certain TCP-based protocols, allows remote attackers to cause a denial…
PriorityP432high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.29%
81.3th percentile
Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to inspect certain TCP-based protocols, allows remote attackers to cause a denial of service (device reboot) via malformed TCP packets.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asa_5500 | — | — |
| cisco | pix_firewall_software | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco PIX and ASA TCP Traffic Inspection Denial of Service Vulnerability
vendor_cisco·2007-02-14·CVSS 7.8
CVE-2007-0959 [HIGH] CWE-119 Cisco PIX and ASA TCP Traffic Inspection Denial of Service Vulnerability
Cisco PIX and ASA TCP Traffic Inspection Denial of Service Vulnerability
Cisco PIX 500 Series Security Appliances and Cisco ASA 5500 Series Adaptive Security Appliances (ASA) contain a vulnerability that could allow an unauthenticated, remote attacker to crash an affected device, causing a denial of service (DoS) condition.
This vulnerability exists due to insufficient handling of malformed TCP packet streams. An unauthenticated, remote attacker could exploit this vulnerability by sending a crafted series of packets to the affected device. This could allow an attacker to crash the device, resulting in a DoS condition.
Cisco confirmed this vulnerability in a security advisory and released updated software.
For a system to be vulnerable, it must be configured for inspection of a TCP-based
GHSA
GHSA-4jr9-pm2m-4f43: Cisco PIX 500 and ASA 5500 Series Security Appliances 7
ghsa_unreviewed·2022-05-01
CVE-2007-0959 [HIGH] GHSA-4jr9-pm2m-4f43: Cisco PIX 500 and ASA 5500 Series Security Appliances 7
Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to inspect certain TCP-based protocols, allows remote attackers to cause a denial of service (device reboot) via malformed TCP packets.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/33062http://secunia.com/advisories/24160http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtmlhttp://www.securityfocus.com/bid/22561http://www.securityfocus.com/bid/22562http://www.securitytracker.com/id?1017651http://www.securitytracker.com/id?1017652http://www.vupen.com/english/advisories/2007/0608https://exchange.xforce.ibmcloud.com/vulnerabilities/32488http://osvdb.org/33062http://secunia.com/advisories/24160http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtmlhttp://www.securityfocus.com/bid/22561http://www.securityfocus.com/bid/22562http://www.securitytracker.com/id?1017651http://www.securitytracker.com/id?1017652http://www.vupen.com/english/advisories/2007/0608https://exchange.xforce.ibmcloud.com/vulnerabilities/32488
2007-02-16
Published