CVE-2007-5570
published 2007-10-18CVE-2007-5570: Cisco Firewall Services Module (FWSM) 3.2(1), and 3.1(5) and earlier, allows remote attackers to cause a denial of service (device reload) via a crafted HTTPS…
PriorityP434high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.22%
86.8th percentile
Cisco Firewall Services Module (FWSM) 3.2(1), and 3.1(5) and earlier, allows remote attackers to cause a denial of service (device reload) via a crafted HTTPS request, aka CSCsi77844.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firewall_services_module | 3.1 – 3.1\(5\) | — |
| cisco | firewall_services_module | 3.2 – 3.2\(1\) | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Firewall Services Module
vendor_cisco·2007-10-17·CVSS 7.8
CVE-2007-5568 [HIGH] CWE-399 Multiple Vulnerabilities in Firewall Services Module
Multiple Vulnerabilities in Firewall Services Module
Two crafted packet vulnerabilities exist in the Cisco Firewall Services
Module (FWSM) that may result in a reload of the FWSM. These vulnerabilities
can be triggered during the processing of HTTPS requests, or during the
processing of Media Gateway Control Protocol (MGCP) packets.
A third vulnerability may cause access control list (ACL) entries to
not be evaluated after the access list has been manipulated.
Note: These vulnerabilities are independent of each other; a device may be
affected by one and not by the others.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20071017-fwsm.
Cisco
Multiple Vulnerabilities in Firewall Services Module
vendor_cisco
CVE-2007-5570 Multiple Vulnerabilities in Firewall Services Module
CVE-2007-5570: Multiple Vulnerabilities in Firewall Services Module
Two crafted packet vulnerabilities exist in the Cisco Firewall Services Module (FWSM) that may result in a reload of the FWSM. These vulnerabilities can be triggered during the processing of HTTPS requests, or during the processing of Media Gateway Control Protocol (MGCP) packets. A third vulnerability may cause access control list (ACL) entries to not be evaluated after the access list has been manipulated. Note: These vulnerabilities are independent of each other; a device may be affected by one and not by the others. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20071017-fwsm .
CWE: CWE-399, CWE-399
Bug IDs: CSCsi77844, CSCsi00694, CSCsi90468, CSCsj5253
GHSA
GHSA-39hh-ghcg-pg9w: Cisco Firewall Services Module (FWSM) 3
ghsa_unreviewed·2022-05-01
CVE-2007-5570 [HIGH] CWE-20 GHSA-39hh-ghcg-pg9w: Cisco Firewall Services Module (FWSM) 3
Cisco Firewall Services Module (FWSM) 3.2(1), and 3.1(5) and earlier, allows remote attackers to cause a denial of service (device reload) via a crafted HTTPS request, aka CSCsi77844.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/27236http://www.cisco.com/en/US/products/products_security_advisory09186a00808dda61.shtmlhttp://www.securityfocus.com/bid/26109http://www.securitytracker.com/id?1018825http://www.vupen.com/english/advisories/2007/3530https://exchange.xforce.ibmcloud.com/vulnerabilities/37251http://secunia.com/advisories/27236http://www.cisco.com/en/US/products/products_security_advisory09186a00808dda61.shtmlhttp://www.securityfocus.com/bid/26109http://www.securitytracker.com/id?1018825http://www.vupen.com/english/advisories/2007/3530https://exchange.xforce.ibmcloud.com/vulnerabilities/37251
2007-10-18
Published