CVE-2007-5571
published 2007-10-18CVE-2007-5571: Cisco Firewall Services Module (FWSM) 3.1(6), and 3.2(2) and earlier, does not properly enforce edited ACLs, which might allow remote attackers to bypass…
PriorityP433medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.76%
75.4th percentile
Cisco Firewall Services Module (FWSM) 3.1(6), and 3.2(2) and earlier, does not properly enforce edited ACLs, which might allow remote attackers to bypass intended restrictions on network traffic, aka CSCsj52536.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firewall_services_module | 3.1 – 3.1\(6\) | — |
| cisco | firewall_services_module | 3.2 – 3.2\(2\) | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Firewall Services Module
vendor_cisco·2007-10-17·CVSS 7.8
CVE-2007-5568 [HIGH] CWE-399 Multiple Vulnerabilities in Firewall Services Module
Multiple Vulnerabilities in Firewall Services Module
Two crafted packet vulnerabilities exist in the Cisco Firewall Services
Module (FWSM) that may result in a reload of the FWSM. These vulnerabilities
can be triggered during the processing of HTTPS requests, or during the
processing of Media Gateway Control Protocol (MGCP) packets.
A third vulnerability may cause access control list (ACL) entries to
not be evaluated after the access list has been manipulated.
Note: These vulnerabilities are independent of each other; a device may be
affected by one and not by the others.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20071017-fwsm.
Cisco
Multiple Vulnerabilities in Firewall Services Module
vendor_cisco
CVE-2007-5571 Multiple Vulnerabilities in Firewall Services Module
CVE-2007-5571: Multiple Vulnerabilities in Firewall Services Module
Two crafted packet vulnerabilities exist in the Cisco Firewall Services Module (FWSM) that may result in a reload of the FWSM. These vulnerabilities can be triggered during the processing of HTTPS requests, or during the processing of Media Gateway Control Protocol (MGCP) packets. A third vulnerability may cause access control list (ACL) entries to not be evaluated after the access list has been manipulated. Note: These vulnerabilities are independent of each other; a device may be affected by one and not by the others. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20071017-fwsm .
CWE: CWE-399, CWE-399
Bug IDs: CSCsi77844, CSCsi00694, CSCsi90468, CSCsj5253
GHSA
GHSA-rvj9-2hjw-96xg: Cisco Firewall Services Module (FWSM) 3
ghsa_unreviewed·2022-05-01
CVE-2007-5571 [MEDIUM] GHSA-rvj9-2hjw-96xg: Cisco Firewall Services Module (FWSM) 3
Cisco Firewall Services Module (FWSM) 3.1(6), and 3.2(2) and earlier, does not properly enforce edited ACLs, which might allow remote attackers to bypass intended restrictions on network traffic, aka CSCsj52536.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/27236http://www.cisco.com/en/US/products/products_security_advisory09186a00808dda61.shtmlhttp://www.securityfocus.com/bid/26109http://www.securitytracker.com/id?1018825http://www.vupen.com/english/advisories/2007/3530https://exchange.xforce.ibmcloud.com/vulnerabilities/37258http://secunia.com/advisories/27236http://www.cisco.com/en/US/products/products_security_advisory09186a00808dda61.shtmlhttp://www.securityfocus.com/bid/26109http://www.securitytracker.com/id?1018825http://www.vupen.com/english/advisories/2007/3530https://exchange.xforce.ibmcloud.com/vulnerabilities/37258
2007-10-18
Published