CVE-2007-0964
published 2007-02-16CVE-2007-0964: Cisco FWSM 3.x before 3.1(3.18), when authentication is configured to use "aaa authentication match" or "aaa authentication include", allows remote attackers…
PriorityP426medium5.4CVSS 2.0
AVNACHAuNCNINAC
EPSS
1.49%
71.3th percentile
Cisco FWSM 3.x before 3.1(3.18), when authentication is configured to use "aaa authentication match" or "aaa authentication include", allows remote attackers to cause a denial of service (device reboot) via a malformed HTTPS request.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firewall_services_module | — | — |
CVSS provenance
nvdv2.05.4MEDIUMAV:N/AC:H/Au:N/C:N/I:N/A:C
vendor_cisco5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Firewall Services Module HTTPS Request Denial of Service Vulnerability
vendor_cisco·2007-02-14·CVSS 5.4
CVE-2007-0964 [MEDIUM] CWE-399 Cisco Firewall Services Module HTTPS Request Denial of Service Vulnerability
Cisco Firewall Services Module HTTPS Request Denial of Service Vulnerability
Cisco Firewall Services Module versions prior to 3.1(3.18) contain a vulnerability that could allow an unauthenticated, remote attacker to create a temporary denial of service (DoS) condition.
The vulnerability is due to an error when handling malformed HTTPS requests on devices that are configured to authenticate users before granting network access. An unauthenticated, remote attacker could exploit this vulnerability by attempting to access an external website utilizing the HTTPS protocol. This action could force Cisco Firewall Services Module to reload, resulting in a temporary DoS condition.
Cisco has confirmed this vulnerability with a security advisory and released updated software.
A successful attack al
GHSA
GHSA-6w7g-rc9r-wg57: Cisco FWSM 3
ghsa_unreviewed·2022-05-01
CVE-2007-0964 [MEDIUM] GHSA-6w7g-rc9r-wg57: Cisco FWSM 3
Cisco FWSM 3.x before 3.1(3.18), when authentication is configured to use "aaa authentication match" or "aaa authentication include", allows remote attackers to cause a denial of service (device reboot) via a malformed HTTPS request.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/24172http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtmlhttp://www.securityfocus.com/bid/22561http://www.vupen.com/english/advisories/2007/0609http://secunia.com/advisories/24172http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtmlhttp://www.securityfocus.com/bid/22561http://www.vupen.com/english/advisories/2007/0609
2007-02-16
Published