CVE-2007-3923
published 2007-07-21CVE-2007-3923: The Common Internet File System (CIFS) optimization in Cisco Wide Area Application Services (WAAS) 4.0.7 and 4.0.9, as used by Cisco WAE appliance and the…
PriorityP431high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.98%
78.2th percentile
The Common Internet File System (CIFS) optimization in Cisco Wide Area Application Services (WAAS) 4.0.7 and 4.0.9, as used by Cisco WAE appliance and the NM-WAE-502 network module, when Edge Services are configured, allows remote attackers to cause a denial of service (loss of service) via a flood of TCP SYN packets to port (1) 139 or (2) 445.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Denial of Service Vulnerability in Cisco Wide Area Application Services (WAAS) Software
vendor_cisco·2007-07-18·CVSS 3.3
CVE-2007-3923 [LOW] CWE-399 Denial of Service Vulnerability in Cisco Wide Area Application Services (WAAS) Software
Denial of Service Vulnerability in Cisco Wide Area Application Services (WAAS) Software
The Cisco Wide Area Application Services (WAAS) software contains a
denial of service (DoS) vulnerability that may cause some devices that run WAAS
software (WAE appliance and NM-WAE-502 module) to stop processing all types of
traffic, including data traffic and management traffic. This condition may
occur if a device running WAAS software is configured for Edge Services, which
utilizes Common Internet File System (CIFS) optimization and receives a flood
of TCP SYN packets on port 139 or 445.
Cisco has made free software available to address this vulnerability
for affected customers. Workarounds are available to mitigate the effects of
this vulnerability.
This advisory is posted at
https://sec.cloudapp
Cisco
Denial of Service Vulnerability in Cisco Wide Area Application Services (WAAS) Software
vendor_cisco
CVE-2007-3923 Denial of Service Vulnerability in Cisco Wide Area Application Services (WAAS) Software
CVE-2007-3923: Denial of Service Vulnerability in Cisco Wide Area Application Services (WAAS) Software
The Cisco Wide Area Application Services (WAAS) software contains a denial of service (DoS) vulnerability that may cause some devices that run WAAS software (WAE appliance and NM-WAE-502 module) to stop processing all types of traffic, including data traffic and management traffic. This condition may occur if a device running WAAS software is configured for Edge Services, which utilizes Common Internet File System (CIFS) optimization and receives a flood of TCP SYN packets on port 139 or 445. Cisco has made free software available to address this vulnerability for affected customers.
CWE: CWE-399, CWE-399
Bug IDs: CSCsi58809
GHSA
GHSA-fv75-9f4p-j7c2: The Common Internet File System (CIFS) optimization in Cisco Wide Area Application Services (WAAS) 4
ghsa_unreviewed·2022-05-01
CVE-2007-3923 [HIGH] GHSA-fv75-9f4p-j7c2: The Common Internet File System (CIFS) optimization in Cisco Wide Area Application Services (WAAS) 4
The Common Internet File System (CIFS) optimization in Cisco Wide Area Application Services (WAAS) 4.0.7 and 4.0.9, as used by Cisco WAE appliance and the NM-WAE-502 network module, when Edge Services are configured, allows remote attackers to cause a denial of service (loss of service) via a flood of TCP SYN packets to port (1) 139 or (2) 445.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/26122http://www.cisco.com/warp/public/707/cisco-sa-20070718-waas.shtmlhttp://www.osvdb.org/36120http://www.securityfocus.com/bid/24956http://www.securitytracker.com/id?1018416http://www.vupen.com/english/advisories/2007/2572https://exchange.xforce.ibmcloud.com/vulnerabilities/35477http://secunia.com/advisories/26122http://www.cisco.com/warp/public/707/cisco-sa-20070718-waas.shtmlhttp://www.osvdb.org/36120http://www.securityfocus.com/bid/24956http://www.securitytracker.com/id?1018416http://www.vupen.com/english/advisories/2007/2572https://exchange.xforce.ibmcloud.com/vulnerabilities/35477
2007-07-21
Published