CVE-2007-0962
published 2007-02-16CVE-2007-0962: Cisco PIX 500 and ASA 5500 Series Security Appliances 7.0 before 7.0(4.14) and 7.1 before 7.1(2.1), and the FWSM 2.x before 2.3(4.12) and 3.x before 3.1(3.24)…
PriorityP432high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.35%
81.8th percentile
Cisco PIX 500 and ASA 5500 Series Security Appliances 7.0 before 7.0(4.14) and 7.1 before 7.1(2.1), and the FWSM 2.x before 2.3(4.12) and 3.x before 3.1(3.24), when "inspect http" is enabled, allows remote attackers to cause a denial of service (device reboot) via malformed HTTP traffic.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asa_5500 | — | — |
| cisco | asa_5500 | — | — |
| cisco | firewall_services_module | — | — |
| cisco | firewall_services_module | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-995f-73jj-h5f7: Cisco PIX 500 and ASA 5500 Series Security Appliances 7
ghsa_unreviewed·2022-05-01
CVE-2007-0962 [HIGH] GHSA-995f-73jj-h5f7: Cisco PIX 500 and ASA 5500 Series Security Appliances 7
Cisco PIX 500 and ASA 5500 Series Security Appliances 7.0 before 7.0(4.14) and 7.1 before 7.1(2.1), and the FWSM 2.x before 2.3(4.12) and 3.x before 3.1(3.24), when "inspect http" is enabled, allows remote attackers to cause a denial of service (device reboot) via malformed HTTP traffic.
Cisco
Cisco Firewall Services Module, PIX, and ASA Malformed HTTP Requests Denial of Service Vulnerability
vendor_cisco·2007-02-14·CVSS 7.8
CVE-2007-0962 [HIGH] CWE-399 Cisco Firewall Services Module, PIX, and ASA Malformed HTTP Requests Denial of Service Vulnerability
Cisco Firewall Services Module, PIX, and ASA Malformed HTTP Requests Denial of Service Vulnerability
Cisco Firewall Services Module, Cisco PIX Security Appliance, and Cisco Adaptive Security Appliance (ASA) contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability exists due to an error within the handling of malformed HTTP requests. An attacker could exploit this vulnerability via a malformed HTTP request to cause the device to reload, resulting in a DoS condition.
Cisco confirmed this vulnerability in a security advisory and released updated software.
Enhanced inspection of HTTP requests is not enabled by default on any of the affected products. Normal inspection, which is enabled by using the inspect h
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/33055http://secunia.com/advisories/24160http://secunia.com/advisories/24180http://securitytracker.com/id?1017651http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtmlhttp://www.securityfocus.com/bid/22561http://www.securityfocus.com/bid/22562http://www.securitytracker.com/id?1017652http://www.vupen.com/english/advisories/2007/0608https://exchange.xforce.ibmcloud.com/vulnerabilities/32486http://osvdb.org/33055http://secunia.com/advisories/24160http://secunia.com/advisories/24180http://securitytracker.com/id?1017651http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtmlhttp://www.securityfocus.com/bid/22561http://www.securityfocus.com/bid/22562http://www.securitytracker.com/id?1017652http://www.vupen.com/english/advisories/2007/0608https://exchange.xforce.ibmcloud.com/vulnerabilities/32486
2007-02-16
Published